Skip to content

meilisearch

v1.43.1 Security

This release includes 1 security fix for security teams reviewing exposed deployments.

Published 22d Search Engines
✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →
This release patches 1 known CVE

Topics

ai api app-search database enterprise-search faceting
+13 more
full-text-search fuzzy-search geosearch hybrid-search instantsearch search search-as-you-type search-engine semantic-search site-search typo-tolerance vector-db vectors

Affected surfaces

auth rce_ssrf

ReleasePort's take

Moderate signal
editorial:auto 13d

Meilisearch v1.43.1 patches an authenticated SSRF vulnerability in request handling. Operators should upgrade to eliminate this attack surface.

Why it matters: Upgrade to v1.43.1 to eliminate the authenticated SSRF vulnerability affecting request handling. Exploitation requires authentication; address to reduce attack surface.

Summary

AI summary

Authenticated SSRF vulnerability fixed

Changes in this release

Security Medium

Authenticated SSRF vulnerability fixed in v1.43.1.

Authenticated SSRF vulnerability fixed in v1.43.1.

Source: llm_adapter@2026-05-21

Confidence: low

Full changelog

Meilisearch v1.43.1 contains a security fix for an authenticated SSRF vulnerability.

No exploitation was found on Meilisearch Cloud. Cloud users are not required to update.

We recommend that self-hosting users upgrade if they allow third parties to configure Meilisearch instances.

We thank Sion Park (@tldhs1144), who reported the issue and suggested a fix, for improving the security of Meilisearch ❤️

Security Fixes

  • Authenticated SSRF vulnerability fixed

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track meilisearch

Get notified when new releases ship.

Sign up free

About meilisearch

A lightning-fast search engine API bringing AI-powered hybrid search to your sites and applications.

All releases →

Beta — feedback welcome: [email protected]