Junglewise Threat Intelligence

CVE-2026-47216: Typesense denial of service in /multi_search endpoint

CVE-2026-47216 · Severity: info · CVSS 8.7 · Published 2026-06-12

Executive brief

Typesense is a search engine used to provide fast, typo-tolerant search results for websites and applications. A vulnerability in its search processing allows an unauthenticated attacker to crash the server by sending a specially crafted request. This results in a complete service outage, preventing users from performing searches until the system is restarted.

Technical details

A denial-of-service vulnerability exists in Typesense's /multi_search endpoint due to improper handling of exceptional conditions (CWE-754). An unauthenticated remote attacker can send a specially crafted network request that triggers an unhandled exception during processing. This exception causes the server process to terminate immediately. The attack requires no prior privileges or user interaction. The vulnerability has been addressed in versions 29.1 and 30.2.

Affected products

  • Typesense Typesense <= 29.0, >= 30.0, < 30.2

Timeline

  • 2026-05-18: advisory: GitHub Security Advisory published
  • 2026-06-12: disclosed: CVE published to NVD

References

Related threats