VYPR

apk package

chainguard/ruby4.0-elasticsearch

pkg:apk/chainguard/ruby4.0-elasticsearch

Vulnerabilities (8)

  • CVE-2026-63263MedJul 22, 2026
    affected < 9.5.0-r0fixed 9.5.0-r0

    Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead to denial of service via Exponential Data Expansion (CAPEC-197). An authenticated user may submit a specially crafted query to the ES|QL engine that causes exponential CPU consumption during query evaluation. B

  • CVE-2026-63144MedJul 21, 2026
    affected < 9.5.0-r0fixed 9.5.0-r0

    Uncontrolled Recursion (CWE-674) in Elasticsearch can lead to denial of service via a specially crafted search request submitted by a low-privileged authenticated user. A user with read-level index access can submit a request that triggers unbounded recursive processing within th

  • CVE-2026-63140MedJul 21, 2026
    affected < 9.5.0-r0fixed 9.5.0-r0

    Reachable Assertion (CWE-617) in Elasticsearch can lead to denial of service via Input Data Manipulation (CAPEC-153). A specially crafted search request containing a null value in a specific query clause causes an internal assertion to be raised during query parsing. Because Elas

  • CVE-2026-56145MedJul 21, 2026
    affected < 9.5.0-r0fixed 9.5.0-r0

    Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead to denial of service via Excessive Allocation (CAPEC-130). A low-privileged authenticated user with permission to execute EQL sequence queries against an index they control can send a specially crafted query th

  • CVE-2026-56144MedJul 21, 2026
    affected < 9.5.0-r0fixed 9.5.0-r0

    Incorrect Authorization (CWE-863) in Elasticsearch can allow an authenticated user with limited index privileges to exploit insufficient authorization controls in the ingest simulation feature. By targeting indices they are not authorized to access directly, the user can cause th

  • CVE-2025-68390MedDec 18, 2025
    affected < 9.3.0-r0fixed 9.3.0-r0

    Allocation of Resources Without Limits or Throttling (CWE-770) in Elasticsearch can allow an authenticated user with snapshot restore privileges to cause Excessive Allocation (CAPEC-130) of memory and a denial of service (DoS) via crafted HTTP request.

  • CVE-2025-68384MedDec 18, 2025
    affected < 9.3.0-r0fixed 9.3.0-r0

    Allocation of Resources Without Limits or Throttling (CWE-770) in Elasticsearch can allow a low-privileged authenticated user to cause Excessive Allocation (CAPEC-130) causing a persistent denial of service (OOM crash) via submission of oversized user settings data.

  • CVE-2025-37731MedDec 15, 2025
    affected < 9.3.0-r0fixed 9.3.0-r0

    Improper Authentication in Elasticsearch PKI realm can lead to user impersonation via specially crafted client certificates. A malicious actor would need to have such a crafted client certificate signed by a legitimate, trusted Certificate Authority.