logstash-9.3

Direct Vulnerabilities

Known vulnerabilities in the logstash-9.3 package. This does not include vulnerabilities belonging to this package’s dependencies.

Fix vulnerabilities automatically

Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.

Fix for free
VulnerabilityVulnerable Version
  • H
CVE-2026-13506

*
  • C
CVE-2026-8763

*
  • L
Allocation of Resources Without Limits or Throttling

*
  • C
Improper Check for Unusual or Exceptional Conditions

*
  • H
Algorithmic Complexity

*
  • L
Interpretation Conflict

*
  • L
Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection')

*
  • L
Uncontrolled Memory Allocation

*
  • L
Improper Input Validation

*
  • L
Uncontrolled Recursion

*
  • L
Improper Input Validation

*
  • L
Improper Certificate Validation

*
  • L
Information Exposure Through Caching

*
  • L
Improper Encoding or Escaping of Output

*
  • M
Use After Free

*
  • L
NULL Pointer Dereference

*
  • L
Heap-based Buffer Overflow

*
  • H
Loop with Unreachable Exit Condition ('Infinite Loop')

*
  • H
HTTP Request Smuggling

*
  • L
Improper Access Control

*
  • M
CRLF Injection

*
  • L
Resource Exhaustion

*
  • L
Resource Exhaustion

*
  • H
Allocation of Resources Without Limits or Throttling

*
  • H
Resource Exhaustion

*
  • L
Improperly Controlled Modification of Dynamically-Determined Object Attributes

*
  • L
GHSA-mhm7-754m-9p8w

*
  • L
Incorrect Authorization

*
  • L
GHSA-r7wm-3cxj-wff9

*
  • L
CVE-2025-14813

*
  • L
Improperly Controlled Modification of Dynamically-Determined Object Attributes

*
  • L
Improperly Controlled Modification of Dynamically-Determined Object Attributes

*
  • L
Incomplete Blacklist

*
  • L
Incorrect Authorization

*
  • L
Server-Side Request Forgery (SSRF)

*
  • L
Incorrect Authorization

*
  • L
Incomplete Blacklist

*
  • L
GHSA-5prr-v3j2-97mh

*
  • L
GHSA-phwj-rprq-35pp

*
  • L
GHSA-p67v-3w7g-wjg7

*
  • L
GHSA-wjv4-x9w8-wm3h

*
  • L
Uncontrolled Recursion

*
  • L
GHSA-5v8h-3h3q-446p

*
  • L
Missing Lock Check

*
  • L
GHSA-8678-w3jw-xfc2

*
  • L
CVE-2026-54905

*
  • L
GHSA-wfpw-mmfh-qq69

*
  • L
GHSA-9cv2-cfxc-v4v2

*
  • H
Loop with Unreachable Exit Condition ('Infinite Loop')

*
  • L
Improper Verification of Cryptographic Signature

*
  • L
HTTP Request Smuggling

*
  • L
Arbitrary Command Injection

*
  • L
Improper Neutralization

*
  • L
Arbitrary Command Injection

*
  • L
Improper Access Control

*
  • L
Allocation of Resources Without Limits or Throttling

*
  • L
Authentication Bypass

*
  • L
Resource Exhaustion

*
  • M
Server-Side Request Forgery (SSRF)

<9.3.5-r0
  • L
Resource Exhaustion

<9.3.4-r1
  • H
HTTP Request Smuggling

<9.3.4-r1
  • L
GHSA-c4rq-3m3g-8wgx

*
  • L
Integer Overflow or Wraparound

<9.3.4-r1
  • C
HTTP Request Smuggling

<9.3.4-r1
  • L
Resource Exhaustion

<9.3.4-r1
  • C
HTTP Request Smuggling

<9.3.4-r1
  • L
GHSA-v2fc-qm4h-8hqv

*
  • H
Missing Report of Error Condition

<9.3.5-r0
  • L
CRLF Injection

<9.3.4-r1
  • M
Allocation of Resources Without Limits or Throttling

<9.3.5-r0
  • M
Arbitrary Command Injection

<9.3.5-r0
  • H
Algorithmic Complexity

<9.3.5-r0
  • C
Arbitrary Command Injection

<9.3.5-r0
  • C
Use of Externally-Controlled Format String

*
  • H
Permissive Regular Expression

<9.3.4-r0
  • M
Interpretation Conflict

<9.3.4-r0
  • H
Resource Exhaustion

<9.3.4-r0
  • M
Interpretation Conflict

<9.3.4-r0
  • M
CRLF Injection

<9.3.4-r0
  • L
Permissive Regular Expression

<9.3.4-r0
  • L
Partial Comparison

<9.3.4-r0
  • L
Incorrect Behavior Order: Validate Before Canonicalize

<9.3.4-r0
  • C
Improper Authentication

<9.3.4-r0
  • L
Resource Exhaustion

<9.3.4-r0
  • H
Resource Exhaustion

<9.3.4-r0
  • M
Improper Validation of Syntactic Correctness of Input

<9.3.4-r0
  • L
Resource Exhaustion

<9.3.4-r0
  • M
Improper Handling of Length Parameter Inconsistency

<9.3.4-r0
  • L
Inefficient Regular Expression Complexity

<9.3.5-r0
  • H
Improper Encoding or Escaping of Output

<9.3.4-r0
  • L
CVE-2026-5588

*
  • H
Improper Output Neutralization for Logs

<9.3.4-r0
  • M
Improper Validation of Certificate with Host Mismatch

<9.3.4-r0
  • H
Improper Encoding or Escaping of Output

<9.3.4-r0
  • L
CVE-2026-0636

*
  • L
CVE-2026-5598

*
  • L
Protection Mechanism Failure

*
  • L
Information Exposure Through Server Log Files

<9.3.3-r0
  • L
Race Condition

<9.3.3-r0
  • L
HTTP Request Smuggling

<9.3.3-r0
  • L
Uncontrolled Recursion

<9.3.2-r0
  • L
GHSA-72hv-8253-57qq

*
  • L
Cross-site Scripting (XSS)

<9.3.1-r0
  • L
GHSA-wx95-c6cv-8532

*
  • L
Directory Traversal

<9.3.1-r0
  • L
Server-Side Request Forgery (SSRF)

<9.3.1-r0
  • L
Arbitrary Code Injection

<9.3.0-r0