CRITICAL9.8CVE-2026-33466Improper Limitation of a Pathname to a Restricted Directory in Logstash Leading to Arbitrary File Write >= 8.0.0, < 8.19.14, >= 9.0.0, < 9.2.8, >= 9.3.0, < 9.3.3
MEDIUM6.5CVE-2025-37730Logstash Improper Certificate Validation in TCP output >= 8.0.0, < 8.18.1, >= 9.0.0, < 9.0.1
MEDIUM5.5CVE-2023-46672Logstash Insertion of Sensitive Information into Log File >= 7.12.1, < 7.12.2, >= 8.10.0, < 8.11.1
LOW3.7In Logstash versions after 6.4.0 and before 6.8.15 and 7.12.0 a TLS certificate validation flaw was found in the monitoring feature.
>= 6.4.0, < 6.8.15, >= 7.0.0, < 7.12.0