CVE Tools

Elasticsearch

93 CVEs tracked. 2 of them are in CISA KEV.

This hub aggregates every CVE we track for Elasticsearch, a product in the databases space. Use it to gauge the current risk picture and drill into individual advisories.

Elasticsearch CVEs per month

Oct 2024 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Elasticsearch CVEs per month
MonthCVEs
2024-100
2024-110
2024-121
2025-011
2025-020
2025-030
2025-042
2025-052
2025-060
2025-070
2025-080
2025-090
2025-101
2025-110
2025-123
2026-010
2026-020
2026-030
2026-040
2026-050
2026-060
2026-079
2026-0814
2026-0911

Severity

How the 93 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.

  • Critical22%
  • High1415%
  • Medium7581%
  • Low22%

Latest CVEs

The 15 most recently published vulnerabilities affecting Elasticsearch.

  1. CVE-2026-94408Uncontrolled Resource Consumption in Elasticsearch Leading to denial of service4.9
  2. CVE-2026-94397Uncontrolled Resource Consumption in Elasticsearch Leading to denial of service6.5
  3. CVE-2026-94396Uncontrolled Resource Consumption in Elasticsearch Leading to denial of service6.5
  4. CVE-2026-94399Uncontrolled Resource Consumption in Elasticsearch Leading to denial of service6.5
  5. CVE-2026-94398Uncontrolled Resource Consumption in Elasticsearch Leading to denial of service6.5
  6. CVE-2026-82300Uncontrolled Resource Consumption in Elasticsearch Leading to Denial of Service6.5
  7. CVE-2026-82294Uncontrolled Resource Consumption in Elasticsearch Leading to Denial of Service6.5
  8. CVE-2026-78607Missing Authorization in Elasticsearch Leading to Information Disclosure5.4
  9. CVE-2026-78605Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') in Elasticsearch Leading to Information Disclosure5.9
  10. CVE-2026-72649Deserialization of Untrusted Data in Elasticsearch Leading to Remote Code Execution8.8
  11. CVE-2026-56143Allocation of Resources Without Limits or Throttling in Elasticsearch Leading to Denial of Service4.9
  12. CVE-2026-72636Uncontrolled Recursion in Elasticsearch Wildcard Matching Leading to Denial of Service6.5
  13. CVE-2026-72642Use of Out-of-range Pointer Offset in the Elasticsearch Machine Learning Native Inference Process8.8
  14. CVE-2026-72639Memory Allocation with Excessive Size Value in Elasticsearch Highlighting Leading to Denial of Service6.5
  15. CVE-2026-72638Uncontrolled Recursion in Elasticsearch Leading to Denial of Service6.5

Product grouping is registry-driven, with AI assist and human review. How it works

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store