flx vulnerabilities
CVEs whose affected-version data names the flx package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
3 CVEsRSS
CVE-2026-4819Medium· 4.9In Search Guard FLX versions from 1.0.0 up to 4.0.1, the audit logging feature might log user credentials from users logging into Kibana.
In Search Guard FLX versions from 1.0.0 up to 4.0.1, the audit logging feature might log user credentials from users logging into Kibana.
▾ Sunlitsearch-guard · flxEPSS 0.21%via NVD
CVE-2026-4818Medium· 6.8In Search Guard FLX versions from 3.0.0 up to 4.0.1, there exists an issue which allows users without the necessary privileges to execute some management operations against data streams.
In Search Guard FLX versions from 3.0.0 up to 4.0.1, there exists an issue which allows users without the necessary privileges to execute some management operations against data streams.
▾ Sunlitsearch-guard · flxEPSS 0.19%via NVD
CVE-2026-4799Medium· 4.3In Search Guard FLX up to version 4.0.1, it is possible to use specially crafted requests to redirect the user to an untrusted URL.
In Search Guard FLX up to version 4.0.1, it is possible to use specially crafted requests to redirect the user to an untrusted URL.
▾ Sunlitsearch-guard · flxEPSS 0.18%via NVD