CVE-2026-47225 Details
Description
Typesense is a fast, typo-tolerant search engine. Prior to versions 29.1 and 30.2, there is a cache isolation issue affecting search requests that use both server-side search result caching and Scoped Search API Keys. Under specific request ordering, cached search results could be reused across requests with different Scoped Search API Key constraints. This could result in a request receiving search results that should have been restricted by its Scoped Search API Key. This issue only affects search requests that use both server-side search result caching and Scoped Search API Keys with embedded filters to restrict access to search results within a collection. This vulnerability may result in unintended disclosure of search results across scoped authorization contexts. This issue has been patched in versions 29.1 and 30.2.
A cache isolation vulnerability has been identified in Typesense, a fast and typo-tolerant search engine. This issue affects versions of Typesense through 29.0 and versions 30.0 prior to 30.2. The vulnerability arises in search requests that utilize both server-side result caching and Scoped Search API Keys with embedded filters. Under certain request orders, cached results could be improperly shared between requests with different Scoped Search API Key constraints, leading to unintended disclosure of search results across scoped authorization contexts. This vulnerability does not impact data integrity or service availability.
Users should upgrade to Typesense version 29.1 or 30.2. If an immediate upgrade is not possible, server-side search result caching can be disabled for requests using Scoped Search API Keys with embedded filters.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jun 12, 2026CISA-ADP
Assessed Jun 12, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/typesense/typesense/security/advisories/GHSA-97x4-gm45-jpcw | [email protected] | AdvisoryRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-524 | Use of Cache Containing Sensitive Information | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Typesense | <= 29.0 >= 30.0, < 30.2 |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 12, 2026 | New CVE Received | [email protected] |
Volerion