Typesense is a fast, typo-tolerant search engine. Prior to versions 29.1 and 30.2, there is an unauthenticated denial-of-service vulnerability in the /multi_search endpoint. A specially crafted request can trigger an unhandled exception during request processing, causing the server process to terminate. This issue can be exploited over the network without authentication and results in service unavailability. The duration of impact may vary depending on system configuration and dataset size. This issue has been patched in versions 29.1 and 30.2.
Metrics
Affected Vendors & Products
References
History
Fri, 12 Jun 2026 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Typesense
Typesense typesense |
|
| Vendors & Products |
Typesense
Typesense typesense |
Fri, 12 Jun 2026 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Typesense is a fast, typo-tolerant search engine. Prior to versions 29.1 and 30.2, there is an unauthenticated denial-of-service vulnerability in the /multi_search endpoint. A specially crafted request can trigger an unhandled exception during request processing, causing the server process to terminate. This issue can be exploited over the network without authentication and results in service unavailability. The duration of impact may vary depending on system configuration and dataset size. This issue has been patched in versions 29.1 and 30.2. | |
| Title | Typesense: Unauthenticated Denial of Service in the Typesense /multi_search Endpoint | |
| Weaknesses | CWE-754 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-06-12T20:19:10.651Z
Reserved: 2026-05-18T22:25:21.258Z
Link: CVE-2026-47216
No data.
Status : Received
Published: 2026-06-12T18:16:34.397
Modified: 2026-06-12T18:16:34.397
Link: CVE-2026-47216
No data.
OpenCVE Enrichment
Updated: 2026-06-12T20:19:30Z