Vulnerabilities
Vulnerable Software
Uncontrolled Resource Consumption in Elasticsearch while evaluating specifically crafted search templates with Mustache functions can lead to Denial of Service by causing the Elasticsearch node to crash.
CVSS Score
6.5
EPSS Score
0.002
Published
2025-05-01
An issue was discovered in Elasticsearch, where a large recursion using the Well-KnownText formatted string with nested GeometryCollection objects could cause a stackoverflow.
CVSS Score
4.9
EPSS Score
0.002
Published
2025-04-08
A flaw was discovered in Elasticsearch, where a large recursion using the innerForbidCircularReferences function of the PatternBank class could cause the Elasticsearch node to crash. A successful attack requires a malicious user to have read_pipeline Elasticsearch cluster privilege assigned to them.
CVSS Score
6.5
EPSS Score
0.001
Published
2025-04-08


Contact Us

Shodan ® - All rights reserved