VYPR

Bitnami package

elasticsearch

pkg:bitnami/elasticsearch

Vulnerabilities (64)

  • CVE-2026-78607MedSep 1, 2026
    affected >= 8.0.0, < 8.19.19fixed 8.19.19

    Missing Authorization (CWE-862) in the Elasticsearch custom inference service can lead to information disclosure via Privilege Abuse (CAPEC-122). A user holding only inference execution privileges could cause outbound inference traffic to be directed to a destination of their cho

  • CVE-2026-78605MedSep 1, 2026
    affected >= 8.18.0, < 8.19.20fixed 8.19.20

    Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') (CWE-444) in Elasticsearch can lead to information disclosure via HTTP Request Smuggling (CAPEC-33). Under specific proxy deployment configurations, a network attacker could obtain confidential responses inte

  • CVE-2026-72649HigSep 1, 2026
    affected >= 8.0.0, < 8.19.20fixed 8.19.20

    Deserialization of Untrusted Data (CWE-502) in the Elasticsearch machine learning component can lead to remote code execution via Object Injection (CAPEC-586). A specially crafted trained model artifact could cause attacker-controlled logic to execute with a materially broader sy

  • CVE-2026-56143MedSep 1, 2026
    affected >= 8.0.0, < 8.19.20fixed 8.19.20

    Allocation of Resources Without Limits or Throttling (CWE-770) in Elasticsearch can lead to a denial of service via Excessive Allocation (CAPEC-130). A user with elevated privileges can submit a specially crafted request that causes excessive memory consumption, which may render

  • CVE-2026-72687MedAug 13, 2026
    affected >= 8.0.0, < 8.19.20fixed 8.19.20

    A flaw in Elasticsearch allows a low-privileged authenticated user to submit a single small request containing a forged opaque identifier. Elasticsearch decodes and deserializes the identifier before confirming that it was legitimately issued by the cluster, and a size value carr

  • CVE-2026-72686MedAug 13, 2026
    affected >= 8.0.0, < 8.19.20fixed 8.19.20

    A flaw in Elasticsearch allows a low-privileged authenticated user to submit a single request containing a crafted user-supplied input. A specific internal component validates the input using a recursive routine and applies no bound to the length of the value being validated, so

  • CVE-2026-72685MedAug 13, 2026
    affected >= 8.0.0, < 8.19.20fixed 8.19.20

    A flaw in Elasticsearch allows a low-privileged authenticated user who can index documents to submit a single small document containing a crafted user-supplied input. Processing one such document occupies a worker thread from a bounded pool for a disproportionate amount of time,

  • CVE-2026-72684MedAug 13, 2026
    affected >= 8.0.0, < 8.19.21fixed 8.19.21

    A flaw in Elasticsearch allows an authenticated user holding only read privileges to submit a small search request containing a crafted user-supplied input. Processing that input causes a specific internal component to allocate memory without any upper bound, and the allocation o

  • CVE-2026-72683MedAug 13, 2026
    affected >= 5.0.0, < 8.19.19fixed 8.19.19

    A flaw in Elasticsearch allows an authenticated user with the privileges required to invoke the simulate pipeline API endpoint (https://www.elastic.co/docs/api/doc/elasticsearch/operation/operation-ingest-simulate) to submit a request that causes a self-referential data structure

  • CVE-2026-72679MedAug 13, 2026
    affected >= 8.19.0, < 8.19.20fixed 8.19.20

    Elasticsearch does not apply its configurable input length restriction to a user-supplied pattern accepted by an intervals query. Compiling a deeply nested pattern drives unbounded recursion that exhausts the thread stack and raises a fatal error, terminating the Elasticsearch no

  • CVE-2026-72678MedAug 13, 2026
    affected >= 8.19.0, < 8.19.20fixed 8.19.20

    Elasticsearch does not validate a size value taken from a user-supplied input before that value is used to reserve memory for an internal data structure. An authenticated user holding only read privileges can submit a single small crafted request to a product API endpoint that ca

  • CVE-2026-72656MedAug 13, 2026
    affected >= 8.11.0, < 8.17.10fixed 8.17.10

    Memory Allocation with Excessive Size Value (CWE-789) in the ES|QL query processing of Elasticsearch can lead to denial of service via Excessive Allocation (CAPEC-130). An authenticated user able to submit ES|QL queries could send a specially crafted query whose evaluation alloca

  • CVE-2026-72647MedAug 13, 2026
    affected >= 8.0.0, < 8.19.20fixed 8.19.20

    Uncontrolled Recursion (CWE-674) in Elasticsearch can lead to denial of service via Serialized Data with Nested Payloads (CAPEC-230). An authenticated user holding only read privileges on a single index can submit one specially crafted search request whose deeply nested structure

  • CVE-2026-72645MedAug 13, 2026
    affected >= 8.0.0, < 8.19.20fixed 8.19.20

    Memory Allocation with Excessive Size Value (CWE-789) in Elasticsearch can lead to denial of service via Excessive Allocation (CAPEC-130). An authenticated user holding only read privileges on a single index can submit one small, specially crafted search request that causes an ex

  • CVE-2026-72642HigAug 13, 2026
    affected >= 8.19.0, < 8.19.20fixed 8.19.20

    The native inference process that Elasticsearch uses to evaluate uploaded machine learning models accepts a model operation that computes a memory address from an offset supplied inside the model, without validating that the offset stays within the bounds of the underlying storag

  • CVE-2026-72639MedAug 13, 2026
    affected >= 8.19.0, < 8.19.20fixed 8.19.20

    Elasticsearch does not enforce an upper bound on a user-supplied count accepted by a search highlighting option, and the allocation derived from that count is not accounted against any circuit breaker. An authenticated user holding only read privileges on a single searchable inde

  • CVE-2026-72638MedAug 13, 2026
    affected >= 8.0.0, < 8.19.20fixed 8.19.20

    Uncontrolled Recursion (CWE-674) in Elasticsearch can lead to denial of service via Input Data Manipulation (CAPEC-153). An authenticated user holding only low-privileged index creation permissions can submit a single request containing a specially crafted, malformed custom analy

  • CVE-2026-72636MedAug 13, 2026
    affected >= 8.0.0, < 8.19.20fixed 8.19.20

    Uncontrolled Recursion (CWE-674) in the Elasticsearch wildcard matching helper can lead to a denial of service via Excessive Allocation (CAPEC-130). The matcher used to resolve wildcard patterns against names is implemented recursively and had no bound on recursion depth or on th

  • CVE-2026-63263MedJul 22, 2026
    affected >= 8.0.0, < 8.19.19fixed 8.19.19

    Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead to denial of service via Exponential Data Expansion (CAPEC-197). An authenticated user may submit a specially crafted query to the ES|QL engine that causes exponential CPU consumption during query evaluation. B

  • CVE-2026-63144MedJul 21, 2026
    affected >= 8.0.0, < 8.19.19fixed 8.19.19

    Uncontrolled Recursion (CWE-674) in Elasticsearch can lead to denial of service via a specially crafted search request submitted by a low-privileged authenticated user. A user with read-level index access can submit a request that triggers unbounded recursive processing within th

Page 1 of 4