Floragunn Search Guard Flx
Don't miss out!
Thousands of developers use stack.watch to stay informed.Get an email whenever new security vulnerabilities are reported in Floragunn Search Guard Flx.
By the Year
In 2026 there have been 0 vulnerabilities in Floragunn Search Guard Flx. Last year, in 2025 Search Guard Flx had 3 security vulnerabilities published. Right now, Search Guard Flx is on track to have less security vulnerabilities in 2026 than it did last year.
| Year | Vulnerabilities | Average Score |
|---|---|---|
| 2026 | 0 | 0.00 |
| 2025 | 3 | 0.00 |
It may take a day or so for new Search Guard Flx vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.
Recent Floragunn Search Guard Flx Security Vulnerabilities
Search Guard FLX DLS bypass in watches before 3.1.2
CVE-2025-12149
- November 14, 2025
In Search Guard FLX versions 3.1.2 and earlier, while Document-Level Security (DLS) is correctly enforced elsewhere, when the search is triggered from a Signals watch, the DLS rule is not enforced, allowing access to all documents in the queried indices.
Information Disclosure
Search Guard <3.1.1: Field Masking IP rule bypass permits data recovery
CVE-2025-12148
- October 29, 2025
In Search Guard versions 3.1.1 and earlier, Field Masking (FM) rules are improperly enforced on fields of type IP (IP Address). While the content of these fields is properly redacted in the _source document returned by search operations, the results do return documents (hits) when searching based on a specific IP values. This allows to reconstruct the original contents of the field. Workaround - If you cannot upgrade immediately, you can avoid the problem by using field level security (FLS) protection on fields of the affected types instead of field masking.
Information Disclosure
Search Guard FLX 3.1: FLS Improperly Enforced on Object Fields
CVE-2025-12147
- October 29, 2025
In Search Guard FLX versions 3.1.1 and earlier, Field-Level Security (FLS) rules are improperly enforced on object-valued fields. When an FLS exclusion rule (e.g., ~field) is applied to a field which contains an object as its value, the object is correctly removed from the _source returned by search operations. However, the object members (i.e., child attributes) remain accessible to search queries. This exposure allows adversaries to infer or reconstruct the original contents of the excluded object. Workaround - If you cannot upgrade immediately and FLS exclusion rules are used for object valued attributes (like ~object), add an additional exclusion rule for the members of the object (like ~object.*).
Information Disclosure
Stay on top of Security Vulnerabilities
Want an email whenever new vulnerabilities are published for Floragunn Search Guard Flx or by Floragunn? Click the Watch button to subscribe.