CVE security advisories and vulnerability history for elasticsearch by elastic.
49
Total CVEs
Published
2
In CISA KEV
Exploited in the wild
4
Public exploits
With known exploit
6.0
Avg CVSS
2014–2025
Last updated
Overview
elastic elasticsearch has 49 published CVE records since 2014, of which 2 are in CISA's Known Exploited Vulnerabilities catalog and 4 have a known public exploit. The average CVSS base score across scored CVEs is 6.0.
This page aggregates every publicly disclosed vulnerability (CVE) affecting elastic elasticsearch, with a severity breakdown, the affected and patched versions, the most common weakness types, and the full CVE list.
Severity and exploitation
How the CVSS severity of elastic elasticsearch's CVEs breaks down, plus how many are exploited in the wild or have public exploit code.
Critical2
High1
Medium21
Low0
25 additional CVEs have no CVSS severity score.
In CISA’s Known Exploited Vulnerabilities catalog
2
2 of elastic elasticsearch's CVEs are confirmed exploited in the wild.
Public exploits
4
4 of elastic elasticsearch's CVEs have a known public exploit available.
Affected versions and CVEs
Browse every elastic elasticsearch version named in a CVE, then pick one to see only the CVEs that affect it.
Common questions about elastic elasticsearch vulnerabilities.
How many CVEs does elastic elasticsearch have?
elastic elasticsearch has 49 published CVE records since 2014.
How many elastic elasticsearch CVEs are in CISA KEV?
Yes — 2 of elastic elasticsearch's CVEs are listed in CISA's Known Exploited Vulnerabilities catalog, confirmed exploited in the wild and carrying a CISA remediation deadline.
Are there public exploits for elastic elasticsearch vulnerabilities?
Yes — 4 of elastic elasticsearch's CVEs have a known public exploit.
Which versions of elastic elasticsearch are affected?
225 distinct elastic elasticsearch versions are named across its CVEs. Use the version filter above to see the CVEs affecting a specific version.
What are the most common weakness types in elastic elasticsearch CVEs?
elastic elasticsearch's CVEs most often map to these CWE weakness types: CWE-200 (Exposure of Sensitive Information to an Unauthorized Actor), CWE-400 (Uncontrolled Resource Consumption), CWE-532 (Insertion of Sensitive Information into Log File), CWE-770 (Allocation of Resources Without Limits or Throttling).
How many critical elastic elasticsearch vulnerabilities are there?
elastic elasticsearch has 2 critical and 1 high-severity CVEs.
What is the average severity of elastic elasticsearch CVEs?
The average CVSS base score across elastic elasticsearch's scored CVEs is 6.0.