Known vulnerabilities in Logstash

Software: Logstash
Software CPE: cpe:2.3:a:elastic_stack:logstash:*:*:*:*:*:*:*:*
Total vulnerabilities: 10
Public exploits: 0
Known exploited (KEV): 0
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting Logstash Logstash is affected by 10 known vulnerabilities: 2 high, 5 medium, 3 low Critical High Medium Low

Vulnerabilities (10)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU125552 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2026-33466
CWE-22 High
No
No
8.19.14, 9.2.8, 9.3.3 09.04.2026 SB2026040925
#VU121007 - Exposure of sensitive information to an unauthorized actor
CVE-2025-66566
CWE-200 Medium
No
No
8.19.10, 9.1.10, 9.2.4 07.01.2026 SB2026010702
SB2026010705
SB2026010706
and 28 more
#VU108738 - Improper Certificate Validation
CVE-2025-37730
CWE-295 Medium
No
No
8.17.6, 8.18.1, 9.0.1 06.05.2025 SB2025050667
#VU101767 - Resource exhaustion
CVE-2024-43380
CWE-400 Medium
No
No
8.15.1 13.12.2024 SB2024121314
SB2025032112
SB2025032126
and 2 more
#VU99358 - Inefficient Regular Expression Complexity
CVE-2024-49761
CWE-1333 Medium
No
No
8.15.3 28.10.2024 SB2024102837
SB2024110504
SB20241108111
and 38 more
#VU98024 - Improper input validation
CVE-2024-47561
CWE-20 High
No
No
8.15.3 03.10.2024 SB2024100351
SB2024100504
SB2024100984
and 36 more
#VU83213 - Information Exposure Through Log Files
CVE-2023-46672
CWE-532 Low
No
No
8.11.1 16.11.2023 SB2023111603
#VU51713 - Improper Certificate Validation
CVE-2021-22138
CWE-295 Medium
No
No
6.8.15, 7.12.0 25.03.2021 SB2021032501
SB2022010520
#VU18087 - Exposure of sensitive information to an unauthorized actor
CVE-2019-7612
CWE-200 Low
No
No
5.6.15, 6.6.1 28.03.2019 SB2019032704
SB2019022503
#VU11472 - Exposure of sensitive information to an unauthorized actor
CVE-2018-3817
CWE-200 Low
No
No
- 03.04.2018 SB2018013026