CVE-2022-23712: Elastic Elasticsearch

High severity, CVSS 7.5. EPSS: 7.6% chance of exploitation in the next 30 days.

A Denial of Service flaw was discovered in Elasticsearch. Using this vulnerability, an unauthenticated attacker could forcibly shut down an Elasticsearch node with a specifically formatted network request.

Affected products

  • Elastic Elasticsearch: from 8.0.0, before 8.2.1 (fixed in 8.2.1)

Published 2022-06-06. Last modified 2026-06-17.