Elasticsearch 8.x — End of Life
Active High riskElasticsearch 8.x is partially supported: only 8.19 still receives security fixes until Jul 15, 2027, in 281 days. The most recent release in this series is 8.19.23. 32 CVEs are tracked for this series. 27 of them were published after the end of life of the affected cycle and will not get an official patch. The next major version is Elasticsearch 9. See Elasticsearch 9 →
Elasticsearch 8.x — All releases
| Version | Released | Active support | EOL date | Latest patch | Status | Alert me |
|---|---|---|---|---|---|---|
| 8.19 | Jul 29, 2025 | — | Jul 15, 2027 | 8.19.23 | Active | |
| 8.18 | Apr 15, 2025 | — | Oct 21, 2025 | 8.18.8 | EOL | |
| 8.17 | Dec 12, 2024 | — | Aug 12, 2025 | 8.17.10 | EOL | |
| 8.16 | Nov 12, 2024 | — | Apr 15, 2025 | 8.16.6 | EOL |
CVEs affecting Elasticsearch 8.x (112)
| CVE | Severity | CVSS | EPSS | KEV | Cycle | Description | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-94408 | MEDIUM | 4.9 | 0.44% | — | 8.17 | Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead denial of service via Excessive Allocation (CAPEC-… | Sep 26, 2026 |
| CVE-2026-94408 | MEDIUM | 4.9 | 0.44% | — | 8.19 | Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead denial of service via Excessive Allocation (CAPEC-… | Sep 26, 2026 |
| CVE-2026-94408 | MEDIUM | 4.9 | 0.44% | — | 8.16 | Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead denial of service via Excessive Allocation (CAPEC-… | Sep 26, 2026 |
| CVE-2026-94408 | MEDIUM | 4.9 | 0.44% | — | 8.18 | Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead denial of service via Excessive Allocation (CAPEC-… | Sep 26, 2026 |
| CVE-2026-94399 | MEDIUM | 6.5 | 0.42% | — | 8.19 | Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead denial of service via Excessive Allocation (CAPEC-… | Sep 26, 2026 |
| CVE-2026-94399 | MEDIUM | 6.5 | 0.42% | — | 8.18 | Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead denial of service via Excessive Allocation (CAPEC-… | Sep 26, 2026 |
| CVE-2026-94399 | MEDIUM | 6.5 | 0.42% | — | 8.17 | Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead denial of service via Excessive Allocation (CAPEC-… | Sep 26, 2026 |
| CVE-2026-94399 | MEDIUM | 6.5 | 0.42% | — | 8.16 | Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead denial of service via Excessive Allocation (CAPEC-… | Sep 26, 2026 |
| CVE-2026-94398 | MEDIUM | 6.5 | 0.42% | — | 8.17 | Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead denial of service via Excessive Allocation (CAPEC-… | Sep 26, 2026 |
| CVE-2026-94398 | MEDIUM | 6.5 | 0.42% | — | 8.16 | Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead denial of service via Excessive Allocation (CAPEC-… | Sep 26, 2026 |
| CVE-2026-94398 | MEDIUM | 6.5 | 0.42% | — | 8.18 | Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead denial of service via Excessive Allocation (CAPEC-… | Sep 26, 2026 |
| CVE-2026-94398 | MEDIUM | 6.5 | 0.42% | — | 8.19 | Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead denial of service via Excessive Allocation (CAPEC-… | Sep 26, 2026 |
| CVE-2026-94397 | MEDIUM | 6.5 | 0.42% | — | 8.16 | Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead denial of service via Excessive Allocation (CAPEC-… | Sep 26, 2026 |
| CVE-2026-94397 | MEDIUM | 6.5 | 0.42% | — | 8.19 | Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead denial of service via Excessive Allocation (CAPEC-… | Sep 26, 2026 |
| CVE-2026-94397 | MEDIUM | 6.5 | 0.42% | — | 8.18 | Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead denial of service via Excessive Allocation (CAPEC-… | Sep 26, 2026 |
| CVE-2026-94397 | MEDIUM | 6.5 | 0.42% | — | 8.17 | Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead denial of service via Excessive Allocation (CAPEC-… | Sep 26, 2026 |
| CVE-2026-82300 | MEDIUM | 6.5 | 0.42% | — | 8.19 | Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead to denial of service via Excessive Allocation (CAP… | Sep 26, 2026 |
| CVE-2026-82300 | MEDIUM | 6.5 | 0.42% | — | 8.17 | Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead to denial of service via Excessive Allocation (CAP… | Sep 26, 2026 |
| CVE-2026-82300 | MEDIUM | 6.5 | 0.42% | — | 8.18 | Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead to denial of service via Excessive Allocation (CAP… | Sep 26, 2026 |
| CVE-2026-82300 | MEDIUM | 6.5 | 0.42% | — | 8.16 | Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead to denial of service via Excessive Allocation (CAP… | Sep 26, 2026 |
| CVE-2026-82294 | MEDIUM | 6.5 | 0.42% | — | 8.17 | Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead to denial of service via Excessive Allocation (CAP… | Sep 26, 2026 |
| CVE-2026-82294 | MEDIUM | 6.5 | 0.42% | — | 8.16 | Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead to denial of service via Excessive Allocation (CAP… | Sep 26, 2026 |
| CVE-2026-82294 | MEDIUM | 6.5 | 0.42% | — | 8.18 | Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead to denial of service via Excessive Allocation (CAP… | Sep 26, 2026 |
| CVE-2026-82294 | MEDIUM | 6.5 | 0.42% | — | 8.19 | Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead to denial of service via Excessive Allocation (CAP… | Sep 26, 2026 |
| CVE-2026-56143 | MEDIUM | 4.9 | 0.44% | — | 8.19 | Allocation of Resources Without Limits or Throttling (CWE-770) in Elasticsearch can lead to a denial of service via Exce… | Sep 1, 2026 |
| CVE-2026-56143 | MEDIUM | 4.9 | 0.44% | — | 8.17 | Allocation of Resources Without Limits or Throttling (CWE-770) in Elasticsearch can lead to a denial of service via Exce… | Sep 1, 2026 |
| CVE-2026-56143 | MEDIUM | 4.9 | 0.44% | — | 8.16 | Allocation of Resources Without Limits or Throttling (CWE-770) in Elasticsearch can lead to a denial of service via Exce… | Sep 1, 2026 |
| CVE-2026-56143 | MEDIUM | 4.9 | 0.44% | — | 8.18 | Allocation of Resources Without Limits or Throttling (CWE-770) in Elasticsearch can lead to a denial of service via Exce… | Sep 1, 2026 |
| CVE-2026-72687 | MEDIUM | 6.5 | 0.42% | — | 8.19 | A flaw in Elasticsearch allows a low-privileged authenticated user to submit a single small request containing a forged … | Aug 13, 2026 |
| CVE-2026-72687 | MEDIUM | 6.5 | 0.42% | — | 8.16 | A flaw in Elasticsearch allows a low-privileged authenticated user to submit a single small request containing a forged … | Aug 13, 2026 |
| CVE-2026-72687 | MEDIUM | 6.5 | 0.42% | — | 8.18 | A flaw in Elasticsearch allows a low-privileged authenticated user to submit a single small request containing a forged … | Aug 13, 2026 |
| CVE-2026-72687 | MEDIUM | 6.5 | 0.42% | — | 8.17 | A flaw in Elasticsearch allows a low-privileged authenticated user to submit a single small request containing a forged … | Aug 13, 2026 |
| CVE-2026-72686 | MEDIUM | 6.5 | 0.56% | — | 8.18 | A flaw in Elasticsearch allows a low-privileged authenticated user to submit a single request containing a crafted user-… | Aug 13, 2026 |
| CVE-2026-72686 | MEDIUM | 6.5 | 0.56% | — | 8.19 | A flaw in Elasticsearch allows a low-privileged authenticated user to submit a single request containing a crafted user-… | Aug 13, 2026 |
| CVE-2026-72686 | MEDIUM | 6.5 | 0.56% | — | 8.16 | A flaw in Elasticsearch allows a low-privileged authenticated user to submit a single request containing a crafted user-… | Aug 13, 2026 |
| CVE-2026-72686 | MEDIUM | 6.5 | 0.56% | — | 8.17 | A flaw in Elasticsearch allows a low-privileged authenticated user to submit a single request containing a crafted user-… | Aug 13, 2026 |
| CVE-2026-72685 | MEDIUM | 4.3 | 0.36% | — | 8.18 | A flaw in Elasticsearch allows a low-privileged authenticated user who can index documents to submit a single small docu… | Aug 13, 2026 |
| CVE-2026-72685 | MEDIUM | 4.3 | 0.36% | — | 8.17 | A flaw in Elasticsearch allows a low-privileged authenticated user who can index documents to submit a single small docu… | Aug 13, 2026 |
| CVE-2026-72685 | MEDIUM | 4.3 | 0.36% | — | 8.19 | A flaw in Elasticsearch allows a low-privileged authenticated user who can index documents to submit a single small docu… | Aug 13, 2026 |
| CVE-2026-72685 | MEDIUM | 4.3 | 0.36% | — | 8.16 | A flaw in Elasticsearch allows a low-privileged authenticated user who can index documents to submit a single small docu… | Aug 13, 2026 |
| CVE-2026-72684 | MEDIUM | 6.5 | 0.42% | — | 8.16 | A flaw in Elasticsearch allows an authenticated user holding only read privileges to submit a small search request conta… | Aug 13, 2026 |
| CVE-2026-72684 | MEDIUM | 6.5 | 0.42% | — | 8.19 | A flaw in Elasticsearch allows an authenticated user holding only read privileges to submit a small search request conta… | Aug 13, 2026 |
| CVE-2026-72684 | MEDIUM | 6.5 | 0.42% | — | 8.17 | A flaw in Elasticsearch allows an authenticated user holding only read privileges to submit a small search request conta… | Aug 13, 2026 |
| CVE-2026-72684 | MEDIUM | 6.5 | 0.42% | — | 8.18 | A flaw in Elasticsearch allows an authenticated user holding only read privileges to submit a small search request conta… | Aug 13, 2026 |
| CVE-2026-72683 | MEDIUM | 6.5 | 0.56% | — | 8.19 | A flaw in Elasticsearch allows an authenticated user with the privileges required to invoke the simulate pipeline API en… | Aug 13, 2026 |
| CVE-2026-72683 | MEDIUM | 6.5 | 0.56% | — | 8.18 | A flaw in Elasticsearch allows an authenticated user with the privileges required to invoke the simulate pipeline API en… | Aug 13, 2026 |
| CVE-2026-72683 | MEDIUM | 6.5 | 0.56% | — | 8.17 | A flaw in Elasticsearch allows an authenticated user with the privileges required to invoke the simulate pipeline API en… | Aug 13, 2026 |
| CVE-2026-72683 | MEDIUM | 6.5 | 0.56% | — | 8.16 | A flaw in Elasticsearch allows an authenticated user with the privileges required to invoke the simulate pipeline API en… | Aug 13, 2026 |
| CVE-2026-72679 | MEDIUM | 6.5 | 0.47% | — | 8.19 | Elasticsearch does not apply its configurable input length restriction to a user-supplied pattern accepted by an interva… | Aug 13, 2026 |
| CVE-2026-72678 | MEDIUM | 6.5 | 0.47% | — | 8.19 | Elasticsearch does not validate a size value taken from a user-supplied input before that value is used to reserve memor… | Aug 13, 2026 |
| CVE-2026-72656 | MEDIUM | 6.5 | 0.42% | — | 8.17 | Memory Allocation with Excessive Size Value (CWE-789) in the ES|QL query processing of Elasticsearch can lead to denial … | Aug 13, 2026 |
| CVE-2026-72656 | MEDIUM | 6.5 | 0.42% | — | 8.18 | Memory Allocation with Excessive Size Value (CWE-789) in the ES|QL query processing of Elasticsearch can lead to denial … | Aug 13, 2026 |
| CVE-2026-72656 | MEDIUM | 6.5 | 0.42% | — | 8.16 | Memory Allocation with Excessive Size Value (CWE-789) in the ES|QL query processing of Elasticsearch can lead to denial … | Aug 13, 2026 |
| CVE-2026-72647 | MEDIUM | 6.5 | 0.42% | — | 8.16 | Uncontrolled Recursion (CWE-674) in Elasticsearch can lead to denial of service via Serialized Data with Nested Payloads… | Aug 13, 2026 |
| CVE-2026-72647 | MEDIUM | 6.5 | 0.42% | — | 8.18 | Uncontrolled Recursion (CWE-674) in Elasticsearch can lead to denial of service via Serialized Data with Nested Payloads… | Aug 13, 2026 |
| CVE-2026-72647 | MEDIUM | 6.5 | 0.42% | — | 8.17 | Uncontrolled Recursion (CWE-674) in Elasticsearch can lead to denial of service via Serialized Data with Nested Payloads… | Aug 13, 2026 |
| CVE-2026-72647 | MEDIUM | 6.5 | 0.42% | — | 8.19 | Uncontrolled Recursion (CWE-674) in Elasticsearch can lead to denial of service via Serialized Data with Nested Payloads… | Aug 13, 2026 |
| CVE-2026-72645 | MEDIUM | 6.5 | 0.42% | — | 8.18 | Memory Allocation with Excessive Size Value (CWE-789) in Elasticsearch can lead to denial of service via Excessive Alloc… | Aug 13, 2026 |
| CVE-2026-72645 | MEDIUM | 6.5 | 0.42% | — | 8.16 | Memory Allocation with Excessive Size Value (CWE-789) in Elasticsearch can lead to denial of service via Excessive Alloc… | Aug 13, 2026 |
| CVE-2026-72645 | MEDIUM | 6.5 | 0.42% | — | 8.19 | Memory Allocation with Excessive Size Value (CWE-789) in Elasticsearch can lead to denial of service via Excessive Alloc… | Aug 13, 2026 |
| CVE-2026-72645 | MEDIUM | 6.5 | 0.42% | — | 8.17 | Memory Allocation with Excessive Size Value (CWE-789) in Elasticsearch can lead to denial of service via Excessive Alloc… | Aug 13, 2026 |
| CVE-2026-72642 | HIGH | 8.8 | 0.60% | — | 8.19 | The native inference process that Elasticsearch uses to evaluate uploaded machine learning models accepts a model operat… | Aug 13, 2026 |
| CVE-2026-72639 | MEDIUM | 6.5 | 0.42% | — | 8.19 | Elasticsearch does not enforce an upper bound on a user-supplied count accepted by a search highlighting option, and the… | Aug 13, 2026 |
| CVE-2026-72638 | MEDIUM | 6.5 | 0.42% | — | 8.18 | Uncontrolled Recursion (CWE-674) in Elasticsearch can lead to denial of service via Input Data Manipulation (CAPEC-153).… | Aug 13, 2026 |
| CVE-2026-72638 | MEDIUM | 6.5 | 0.42% | — | 8.16 | Uncontrolled Recursion (CWE-674) in Elasticsearch can lead to denial of service via Input Data Manipulation (CAPEC-153).… | Aug 13, 2026 |
| CVE-2026-72638 | MEDIUM | 6.5 | 0.42% | — | 8.19 | Uncontrolled Recursion (CWE-674) in Elasticsearch can lead to denial of service via Input Data Manipulation (CAPEC-153).… | Aug 13, 2026 |
| CVE-2026-72638 | MEDIUM | 6.5 | 0.42% | — | 8.17 | Uncontrolled Recursion (CWE-674) in Elasticsearch can lead to denial of service via Input Data Manipulation (CAPEC-153).… | Aug 13, 2026 |
| CVE-2026-72636 | MEDIUM | 6.5 | 0.41% | — | 8.19 | Uncontrolled Recursion (CWE-674) in the Elasticsearch wildcard matching helper can lead to a denial of service via Exces… | Aug 13, 2026 |
| CVE-2026-72636 | MEDIUM | 6.5 | 0.41% | — | 8.18 | Uncontrolled Recursion (CWE-674) in the Elasticsearch wildcard matching helper can lead to a denial of service via Exces… | Aug 13, 2026 |
| CVE-2026-72636 | MEDIUM | 6.5 | 0.41% | — | 8.17 | Uncontrolled Recursion (CWE-674) in the Elasticsearch wildcard matching helper can lead to a denial of service via Exces… | Aug 13, 2026 |
| CVE-2026-72636 | MEDIUM | 6.5 | 0.41% | — | 8.16 | Uncontrolled Recursion (CWE-674) in the Elasticsearch wildcard matching helper can lead to a denial of service via Exces… | Aug 13, 2026 |
| CVE-2026-63263 | MEDIUM | 6.5 | 0.42% | — | 8.18 | Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead to denial of service via Exponential Data Expansio… | Jul 22, 2026 |
| CVE-2026-63263 | MEDIUM | 6.5 | 0.42% | — | 8.16 | Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead to denial of service via Exponential Data Expansio… | Jul 22, 2026 |
| CVE-2026-63263 | MEDIUM | 6.5 | 0.42% | — | 8.17 | Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead to denial of service via Exponential Data Expansio… | Jul 22, 2026 |
| CVE-2026-63263 | MEDIUM | 6.5 | 0.42% | — | 8.19 | Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead to denial of service via Exponential Data Expansio… | Jul 22, 2026 |
| CVE-2026-63144 | MEDIUM | 6.5 | 0.42% | — | 8.19 | Uncontrolled Recursion (CWE-674) in Elasticsearch can lead to denial of service via a specially crafted search request s… | Jul 21, 2026 |
| CVE-2026-63140 | MEDIUM | 6.5 | 0.42% | — | 8.17 | Reachable Assertion (CWE-617) in Elasticsearch can lead to denial of service via Input Data Manipulation (CAPEC-153). A … | Jul 21, 2026 |
| CVE-2026-63140 | MEDIUM | 6.5 | 0.42% | — | 8.18 | Reachable Assertion (CWE-617) in Elasticsearch can lead to denial of service via Input Data Manipulation (CAPEC-153). A … | Jul 21, 2026 |
| CVE-2026-63140 | MEDIUM | 6.5 | 0.42% | — | 8.19 | Reachable Assertion (CWE-617) in Elasticsearch can lead to denial of service via Input Data Manipulation (CAPEC-153). A … | Jul 21, 2026 |
| CVE-2026-63140 | MEDIUM | 6.5 | 0.42% | — | 8.16 | Reachable Assertion (CWE-617) in Elasticsearch can lead to denial of service via Input Data Manipulation (CAPEC-153). A … | Jul 21, 2026 |
| CVE-2026-63136 | MEDIUM | 6.5 | 0.42% | — | 8.19 | Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead to denial of service via Excessive Allocation (CAP… | Jul 21, 2026 |
| CVE-2026-63136 | MEDIUM | 6.5 | 0.42% | — | 8.16 | Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead to denial of service via Excessive Allocation (CAP… | Jul 21, 2026 |
| CVE-2026-63136 | MEDIUM | 6.5 | 0.42% | — | 8.17 | Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead to denial of service via Excessive Allocation (CAP… | Jul 21, 2026 |
| CVE-2026-63136 | MEDIUM | 6.5 | 0.42% | — | 8.18 | Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead to denial of service via Excessive Allocation (CAP… | Jul 21, 2026 |
| CVE-2026-56145 | MEDIUM | 6.5 | 0.47% | — | 8.17 | Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead to denial of service via Excessive Allocation (CAP… | Jul 21, 2026 |
| CVE-2026-56145 | MEDIUM | 6.5 | 0.47% | — | 8.19 | Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead to denial of service via Excessive Allocation (CAP… | Jul 21, 2026 |
| CVE-2026-56145 | MEDIUM | 6.5 | 0.47% | — | 8.16 | Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead to denial of service via Excessive Allocation (CAP… | Jul 21, 2026 |
| CVE-2026-56145 | MEDIUM | 6.5 | 0.47% | — | 8.18 | Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead to denial of service via Excessive Allocation (CAP… | Jul 21, 2026 |
| CVE-2026-56144 | MEDIUM | 5.3 | 0.32% | — | 8.18 | Incorrect Authorization (CWE-863) in Elasticsearch can allow an authenticated user with limited index privileges to expl… | Jul 21, 2026 |
| CVE-2026-56144 | MEDIUM | 5.3 | 0.32% | — | 8.19 | Incorrect Authorization (CWE-863) in Elasticsearch can allow an authenticated user with limited index privileges to expl… | Jul 21, 2026 |
| CVE-2026-56144 | MEDIUM | 5.3 | 0.32% | — | 8.16 | Incorrect Authorization (CWE-863) in Elasticsearch can allow an authenticated user with limited index privileges to expl… | Jul 21, 2026 |
| CVE-2026-56144 | MEDIUM | 5.3 | 0.32% | — | 8.17 | Incorrect Authorization (CWE-863) in Elasticsearch can allow an authenticated user with limited index privileges to expl… | Jul 21, 2026 |
| CVE-2026-56149 | MEDIUM | 4.9 | 0.50% | — | 8.16 | Allocation of Resources Without Limits or Throttling (CWE-770) in Elasticsearch can lead to a denial of service via Exce… | Jul 1, 2026 |
| CVE-2026-56149 | MEDIUM | 4.9 | 0.50% | — | 8.19 | Allocation of Resources Without Limits or Throttling (CWE-770) in Elasticsearch can lead to a denial of service via Exce… | Jul 1, 2026 |
| CVE-2026-56149 | MEDIUM | 4.9 | 0.50% | — | 8.17 | Allocation of Resources Without Limits or Throttling (CWE-770) in Elasticsearch can lead to a denial of service via Exce… | Jul 1, 2026 |
| CVE-2026-56149 | MEDIUM | 4.9 | 0.50% | — | 8.18 | Allocation of Resources Without Limits or Throttling (CWE-770) in Elasticsearch can lead to a denial of service via Exce… | Jul 1, 2026 |
| CVE-2026-56148 | MEDIUM | 6.5 | 0.47% | — | 8.16 | Uncontrolled Recursion (CWE-674) in Elasticsearch can lead to a denial of service via Excessive Allocation (CAPEC-130). … | Jul 1, 2026 |
| CVE-2026-56148 | MEDIUM | 6.5 | 0.47% | — | 8.18 | Uncontrolled Recursion (CWE-674) in Elasticsearch can lead to a denial of service via Excessive Allocation (CAPEC-130). … | Jul 1, 2026 |
| CVE-2026-56148 | MEDIUM | 6.5 | 0.47% | — | 8.19 | Uncontrolled Recursion (CWE-674) in Elasticsearch can lead to a denial of service via Excessive Allocation (CAPEC-130). … | Jul 1, 2026 |
| CVE-2026-56148 | MEDIUM | 6.5 | 0.47% | — | 8.17 | Uncontrolled Recursion (CWE-674) in Elasticsearch can lead to a denial of service via Excessive Allocation (CAPEC-130). … | Jul 1, 2026 |
| CVE-2025-68390 | MEDIUM | 4.9 | 0.37% | — | 8.19 | Allocation of Resources Without Limits or Throttling (CWE-770) in Elasticsearch can allow an authenticated user with sna… | Dec 18, 2025 |
| CVE-2025-68390 | MEDIUM | 4.9 | 0.37% | — | 8.16 | Allocation of Resources Without Limits or Throttling (CWE-770) in Elasticsearch can allow an authenticated user with sna… | Dec 18, 2025 |
| CVE-2025-68390 | MEDIUM | 4.9 | 0.37% | — | 8.17 | Allocation of Resources Without Limits or Throttling (CWE-770) in Elasticsearch can allow an authenticated user with sna… | Dec 18, 2025 |
| CVE-2025-68390 | MEDIUM | 4.9 | 0.37% | — | 8.18 | Allocation of Resources Without Limits or Throttling (CWE-770) in Elasticsearch can allow an authenticated user with sna… | Dec 18, 2025 |
| CVE-2025-68384 | MEDIUM | 6.5 | 0.32% | — | 8.19 | Allocation of Resources Without Limits or Throttling (CWE-770) in Elasticsearch can allow a low-privileged authenticated… | Dec 18, 2025 |
| CVE-2025-68384 | MEDIUM | 6.5 | 0.32% | — | 8.16 | Allocation of Resources Without Limits or Throttling (CWE-770) in Elasticsearch can allow a low-privileged authenticated… | Dec 18, 2025 |
| CVE-2025-68384 | MEDIUM | 6.5 | 0.32% | — | 8.18 | Allocation of Resources Without Limits or Throttling (CWE-770) in Elasticsearch can allow a low-privileged authenticated… | Dec 18, 2025 |
| CVE-2025-68384 | MEDIUM | 6.5 | 0.32% | — | 8.17 | Allocation of Resources Without Limits or Throttling (CWE-770) in Elasticsearch can allow a low-privileged authenticated… | Dec 18, 2025 |
| CVE-2025-37731 | MEDIUM | 6.8 | 0.19% | — | 8.18 | Improper Authentication in Elasticsearch PKI realm can lead to user impersonation via specially crafted client certifica… | Dec 15, 2025 |
| CVE-2025-37731 | MEDIUM | 6.8 | 0.19% | — | 8.17 | Improper Authentication in Elasticsearch PKI realm can lead to user impersonation via specially crafted client certifica… | Dec 15, 2025 |
| CVE-2025-37731 | MEDIUM | 6.8 | 0.19% | — | 8.19 | Improper Authentication in Elasticsearch PKI realm can lead to user impersonation via specially crafted client certifica… | Dec 15, 2025 |
| CVE-2025-37731 | MEDIUM | 6.8 | 0.19% | — | 8.16 | Improper Authentication in Elasticsearch PKI realm can lead to user impersonation via specially crafted client certifica… | Dec 15, 2025 |
Elasticsearch 8.x will reach end of life — migrate to Elasticsearch 9.x
Elasticsearch 9.x is the next major release. Plan your upgrade before Elasticsearch 8.x stops receiving security patches.
Add a Elasticsearch 8 EOL badge to your README
Show your users which Elasticsearch version your project runs and whether it is still supported. The badge updates automatically. More formats and options →
[](https://eolcanary.com/explore/elasticsearch/8)Frequently asked questions
Is Elasticsearch 8 end of life?
Partially. 3 of the 4 Elasticsearch 8.x releases have reached end of life. Still supported: 8.19 (until July 15, 2027 at the latest).
What CVEs affect Elasticsearch 8?
There are 32 CVEs tracked for Elasticsearch 8.x. See the full list above with CVSS and EPSS scores.
What is the latest Elasticsearch 8 version?
The latest Elasticsearch 8.x patch release is 8.19.23, released on October 6, 2026. Always run the latest patch to benefit from all security fixes.
How to migrate from Elasticsearch 8 to Elasticsearch 9?
To migrate from Elasticsearch 8 to Elasticsearch 9: (1) review the official Elasticsearch 9 migration guide for breaking changes, (2) update dependencies and configuration accordingly, (3) test thoroughly in a staging environment, (4) deploy with a rollback plan. Starting early gives you time to resolve compatibility issues before your current version reaches end of life.
Is it safe to run Elasticsearch 8 in production?
Only on a supported release (8.19). Support for Elasticsearch 8.19 ends on July 15, 2027. Make sure you run the latest patch (8.19.23) to have all security fixes applied.
Data sourced from endoflife.date · CVE data from NVD · EPSS from FIRST.org · KEV from CISA
