CVE Tools

Elasticsearch

8 CVEs tracked since 2015. Since May 2015, none of them reached CISA KEV.

Elasticsearch CVEs per month

May 2015 to Sep 2017. Point at a month, or focus the strip and use the arrow keys.
Elasticsearch CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2015-0510
2015-06null or fewer
2015-07null or fewer
2015-0810
2015-09null or fewer
2015-10null or fewer
2015-11null or fewer
2015-12null or fewer
2016-01null or fewer
2016-02null or fewer
2016-03null or fewer
2016-04null or fewer
2016-05null or fewer
2016-06null or fewer
2016-07null or fewer
2016-08null or fewer
2016-09null or fewer
2016-10null or fewer
2016-11null or fewer
2016-12null or fewer
2017-01null or fewer
2017-02null or fewer
2017-03null or fewer
2017-04null or fewer
2017-05null or fewer
2017-06null or fewer
2017-07null or fewer
2017-0830
2017-0930

Products

The products that kept showing up in Elasticsearch's monthly top three, with their CVEs summed over those months.

  1. Elasticsearch33 months
  2. Logstash22 months
  3. Cloud Enterprise11 month
  4. Kibana11 month
  5. X-pack11 month

Latest CVEs

The 15 most recently published vulnerabilities affecting Elasticsearch.

  1. CVE-2026-26933Improper Validation of Array Index in Packetbeat Leading to Denial of Service5.7
  2. CVE-2025-68382Packetbeat Out-of-bounds Read6.5
  3. CVE-2025-68381Packetbeat Improper Bounds Check6.5
  4. CVE-2025-68388Allocation of resources without limits or throttling (CWE-770) allows an unauthenticated remote attacker to cause excessive allocation (CAPEC-130) of memory and CPU via the integration of malicious...5.3
  5. CVE-2020-7016Kibana versions before 6.8.11 and 7.8.1 contain a denial of service (DoS) flaw in Timelion. An attacker can construct a URL that when viewed by a Kibana user can lead to the Kibana process consumin...4.8
  6. CVE-2020-7017In Kibana versions before 6.8.11 and 7.8.1 the region map visualization in contains a stored XSS flaw. An attacker who is able to edit or create a region map visualization could obtain sensitive in...6.7
  7. CVE-2017-11480Packetbeat versions prior to 5.6.4 are affected by a denial of service flaw in the PostgreSQL protocol handler. If Packetbeat is listening for PostgreSQL traffic and a user is able to send arbitrar...7.5
  8. CVE-2017-8444The client-forwarder in Elastic Cloud Enterprise versions prior to 1.0.2 do not properly encrypt traffic to ZooKeeper. If an attacker is able to man in the middle (MITM) the traffic between the cli...5.9
  9. CVE-2017-11479Kibana versions prior to 5.6.1 had a cross-site scripting (XSS) vulnerability in Timelion that could allow an attacker to obtain sensitive information from or perform destructive actions on behalf ...6.1
  10. CVE-2017-14730The init script in the Gentoo app-admin/logstash-bin package before 5.5.3 and 5.6.x before 5.6.1 has "chown -R" calls for user-writable directory trees, which allows local users to gain privileges ...7.8
  11. CVE-2017-8446The Reporting feature in X-Pack in versions prior to 5.5.2 and standalone Reporting plugin versions versions prior to 2.4.6 had an impersonation vulnerability. A user with the reporting_user role c...5.3
  12. CVE-2015-5619Logstash 1.4.x before 1.4.5 and 1.5.x before 1.5.4 with Lumberjack output or the Logstash forwarder does not validate SSL/TLS certificates from the Logstash server, which might allow attackers to o...5.9
  13. CVE-2015-4165The snapshot API in Elasticsearch before 1.6.0 when another application exists on the system that can read Lucene files and execute code from them, is accessible by the attacker, and the Java VM on...7.5
  14. CVE-2015-5378Logstash 1.5.x before 1.5.3 and 1.4.x before 1.4.4 allows remote attackers to read communications between Logstash Forwarder agent and Logstash server.7.5
  15. CVE-2016-10362Prior to Logstash version 5.0.1, Elasticsearch Output plugin when updating connections after sniffing, would log to file HTTP basic auth credentials.6.5

The record

Peak rank
#82 in May 2015
Busiest month shown
Aug 2017, 3 CVEs
Months with a KEV entry
0 since May 2015
Monthly snapshots
4 since 2015
Elasticsearch's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store