← Back to browse · API

CVE-2023-31419

Severity
MEDIUM
CVSS
6.5
EPSS
0.60679
Risk score
47.24
CISA KEV
No
PoC
No
Published
2023-10-26
Modified
2025-02-13
First seen
2026-08-07
Aliases
EUVD-2023-2797, GHSA-QWRX-45XF-JJF7
Products
Elastic:Elasticsearch 7.0.0 <7.17.12, Elastic:Elasticsearch 8.0.0 <8.9.0
Sources
euvd EUVD-2023-2797

Description

A flaw was discovered in Elasticsearch, affecting the _search API that allowed a specially crafted query string to cause a Stack Overflow and ultimately a Denial of Service.

References