CVE Explorer
CVE-2026-47216
Typesense is a fast, typo-tolerant search engine. Prior to versions 29.1 and 30.2, there is an unauthenticated denial-of-service vulnerability in the /multi_search endpoint. A specially crafted request can trigger an unhandled exception during request processing, causing the server process to terminate. This issue can be exploited over the network without authentication and results in service unavailability. The duration of impact may vary depending on system configuration and dataset size. This
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"product":"typesense","vendor":"typesense","versions":[{"status":"affected","version":"< 29.1"},{"status":"affected","version":">= 30.0, < 30.2"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:5cb2185125e06f7eed4ad9a985bbd8af22fd5ea391d0eda486dbe09cdfedc664 · sha256:77fde137dcf13af4… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackRequirements":"NONE","attackVector":"NETWORK","baseScore":8.7,"baseSeverity":"HIGH","privilegesRequired":"NONE","subAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","userInteraction":"NONE","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N","version":"4.0","vulnAvailabilityImpact":"HIGH","vulnConfidentialityImpact":"NONE","vulnIntegrityImpact":"NONE"},"metric_type":"cvssV4_0"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:5cb2185125e06f7eed4ad9a985bbd8af22fd5ea391d0eda486dbe09cdfedc664 · sha256:77fde137dcf13af4… · /containers/cna/metrics/0/cvssV4_0
CWE assertions
1 source assertion{"cweId":"CWE-754","description":"CWE-754: Improper Check for Unusual or Exceptional Conditions","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:5cb2185125e06f7eed4ad9a985bbd8af22fd5ea391d0eda486dbe09cdfedc664 · sha256:77fde137dcf13af4… · /containers/cna/problemTypes/0/descriptions/0
Source references
1 source assertion{"name":"https://github.com/typesense/typesense/security/advisories/GHSA-fpx5-8c99-247j","tags":["x_refsource_CONFIRM"],"url":"https://github.com/typesense/typesense/security/advisories/GHSA-fpx5-8c99-247j"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:5cb2185125e06f7eed4ad9a985bbd8af22fd5ea391d0eda486dbe09cdfedc664 · sha256:77fde137dcf13af4… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.