← Vulnerability feed

Vulnerability record · CVE-2021-22145 · published 21 July 2021

CVE-2021-22145: Elasticsearch error reporting memory disclosure leaks buffer contents

Elastic · Elasticsearch

Elasticsearch 7.10.0 through 7.13.3 returns error messages for malformed queries that include previously used portions of a data buffer. That buffer can hold sensitive content such as Elasticsearch documents or authentication details, so an error path becomes an information leak.

6.5 CVSS 3.1 Medium EPSS 76% · top 0.5% CWE-200 · Information exposureCWE-209 · Error message information leak
6.5CVSS 3.1 base score, v2 4.0
76%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
9References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

A memory disclosure vulnerability was identified in Elasticsearch 7.10.0 to 7.13.3 error reporting. A user with the ability to submit arbitrary queries to Elasticsearch could submit a malformed query that would result in an error message returned containing previously used portions of a data buffer. This buffer could contain sensitive information such as Elasticsearch documents or authentication details.

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: high.

high priorityThe flaw is remotely reachable with low privileges, leaks sensitive data, has a public exploit reference and a very high EPSS score, though it is not in KEV.

What it is

Elasticsearch 7.10.0 through 7.13.3 returns error messages for malformed queries that include previously used portions of a data buffer. That buffer can hold sensitive content such as Elasticsearch documents or authentication details, so an error path becomes an information leak.

Impact

An attacker who can submit queries gains read access to memory-resident data, potentially including indexed documents and authentication details, without modifying or disrupting the service.

Attack surface

Reached over the network by submitting a malformed query to Elasticsearch; the CVSS vector requires low privileges (PR:L) and no user interaction. Any account able to send arbitrary queries is sufficient.

Exploitation

Not listed in CISA KEV, but EPSS is 0.76249 (99.51st percentile) and a public Packet Storm exploit reference exists, indicating high likelihood and available proof-of-concept code.

What to do

  • Upgrade Elasticsearch to 7.13.4 or later, which the vendor advisory identifies as the fixed release.
  • Apply the Oracle CPU April 2022 updates for affected Oracle products that bundle Elasticsearch.
  • Restrict query submission to trusted, authenticated users and remove anonymous or overly broad read access.
  • Review and sanitize error responses returned to clients so internal buffer content is not exposed.

Detection

  • Monitor Elasticsearch logs for repeated malformed-query errors and error responses containing unexpected binary or document-like content.
  • Alert on anomalous query patterns from a single account, especially bursts of deliberately invalid queries.
  • Inspect outbound error payloads for strings resembling credentials, tokens or indexed document fields.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2021-22145 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2022-22963Spring Cloud Function routing expression SpEL injection RCESpring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions allow a user to supply a crafted SpEL expression as a routing-expression w…KEVEPSS 100%analysed9.8CVE-2022-22965Spring Framework data binding remote code execution (Spring4Shell)Spring MVC and Spring WebFlux applications on JDK 9+ can be exploited through data binding to achieve remote code execution. The known exploit path r…KEVEPSS 100%analysed9.8CVE-2017-1000353Jenkins CLI Java deserialization allows unauthenticated remote code executionJenkins 2.56 and earlier, and 2.46.1 LTS and earlier, deserialize attacker-supplied Java SignedObject data sent to the Jenkins CLI, bypassing the exi…KEVEPSS 100%analysed9.8CVE-2015-1427Elasticsearch Groovy scripting engine sandbox escape RCEThe Groovy scripting engine in Elasticsearch before 1.3.8 and 1.4.x before 1.4.3 fails to enforce its sandbox, letting a crafted script execute arbit…KEVEPSS 100%analysed8.5CVE-2021-39144XStream deserialization allows remote command executionXStream, a Java library that serializes objects to and from XML, can execute host commands when a remote attacker with sufficient rights manipulates …KEVEPSS 98%analysed8.1CVE-2014-3120Elasticsearch dynamic scripting allows remote code executionThe default configuration in Elasticsearch before 1.2 enables dynamic scripting, so the source parameter to _search can execute arbitrary MVEL expres…KEVEPSS 89%analysed9.8CVE-2021-29921Python vulnerabilityIn Python before 3,9,5, the ipaddress library mishandles leading zero characters in the octets of an IP address string. This (in some situations) all…EPSS 6.9%9.8CVE-2015-5377Elasticsearch injection vulnerabilityElasticsearch before 1.6.1 allows remote attackers to execute arbitrary code via unspecified vectors involving the transport protocol. NOTE: ZDI appe…EPSS 14%

Source: NIST National Vulnerability Database (record CVE-2021-22145), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.