CVE-2024-23450: Elastic Elasticsearch

High severity, CVSS 7.5. EPSS: 1.3% chance of exploitation in the next 30 days.

A flaw was discovered in Elasticsearch, where processing a document in a deeply nested pipeline on an ingest node could cause the Elasticsearch node to crash.

Affected products

  • Elastic Elasticsearch: from 7.0.0, before 7.17.19 (fixed in 7.17.19); from 8.0.0, before 8.13.0 (fixed in 8.13.0)

Published 2024-03-27. Last modified 2026-06-17.