CVE-2026-47216 Details
Description
Typesense is a fast, typo-tolerant search engine. Prior to versions 29.1 and 30.2, there is an unauthenticated denial-of-service vulnerability in the /multi_search endpoint. A specially crafted request can trigger an unhandled exception during request processing, causing the server process to terminate. This issue can be exploited over the network without authentication and results in service unavailability. The duration of impact may vary depending on system configuration and dataset size. This issue has been patched in versions 29.1 and 30.2.
A denial-of-service vulnerability has been identified in Typesense, a fast and typo-tolerant search engine. This issue affects versions of Typesense through 29.0 and versions 30.0 prior to 30.2. The vulnerability is located in the '/multi_search' endpoint, where a specially crafted request can cause an unhandled exception during processing. This exception leads to the termination of the server process, causing service unavailability. The vulnerability can be exploited over the network without authentication, and the duration of the impact may vary based on system configuration and dataset size.
Users are advised to upgrade to Typesense versions 29.1 or 30.2, as this vulnerability has been patched in these releases.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jun 12, 2026CISA-ADP
Assessed Jun 12, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/typesense/typesense/security/advisories/GHSA-fpx5-8c99-247j | [email protected] | AdvisoryRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-754 | Improper Check for Unusual or Exceptional Conditions | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Typesense | <= 29.0 >= 30.0, < 30.2 |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 12, 2026 | New CVE Received | [email protected] |
Volerion