Elasticsearch 8.x — End of Life
Active Medium riskElasticsearch 8.x — All releases
| Version | Released | Active support | EOL date | Latest patch | Status | Alert me |
|---|---|---|---|---|---|---|
| 8.19 | Jul 23, 2025 | — | Jul 15, 2027 | 8.19.19 | Active | |
| 8.18 | Apr 10, 2025 | — | Oct 21, 2025 | 8.18.8 | EOL | |
| 8.17 | Dec 11, 2024 | — | Aug 5, 2025 | 8.17.10 | EOL | |
| 8.16 | Nov 8, 2024 | — | Apr 15, 2025 | 8.16.6 | EOL |
CVEs affecting Elasticsearch 8.x (20)
| CVE | Severity | CVSS | EPSS | KEV | Cycle | Description | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-56149 | MEDIUM | 4.9 | 0.32% | — | 8.16 | Allocation of Resources Without Limits or Throttling (CWE-770) in Elasticsearch can lead to a denial of service via Exce… | Jul 1, 2026 |
| CVE-2026-56149 | MEDIUM | 4.9 | 0.32% | — | 8.17 | Allocation of Resources Without Limits or Throttling (CWE-770) in Elasticsearch can lead to a denial of service via Exce… | Jul 1, 2026 |
| CVE-2026-56149 | MEDIUM | 4.9 | 0.32% | — | 8.19 | Allocation of Resources Without Limits or Throttling (CWE-770) in Elasticsearch can lead to a denial of service via Exce… | Jul 1, 2026 |
| CVE-2026-56149 | MEDIUM | 4.9 | 0.32% | — | 8.18 | Allocation of Resources Without Limits or Throttling (CWE-770) in Elasticsearch can lead to a denial of service via Exce… | Jul 1, 2026 |
| CVE-2026-56148 | MEDIUM | 6.5 | 0.35% | — | 8.16 | Uncontrolled Recursion (CWE-674) in Elasticsearch can lead to a denial of service via Excessive Allocation (CAPEC-130). … | Jul 1, 2026 |
| CVE-2026-56148 | MEDIUM | 6.5 | 0.35% | — | 8.18 | Uncontrolled Recursion (CWE-674) in Elasticsearch can lead to a denial of service via Excessive Allocation (CAPEC-130). … | Jul 1, 2026 |
| CVE-2026-56148 | MEDIUM | 6.5 | 0.35% | — | 8.17 | Uncontrolled Recursion (CWE-674) in Elasticsearch can lead to a denial of service via Excessive Allocation (CAPEC-130). … | Jul 1, 2026 |
| CVE-2026-56148 | MEDIUM | 6.5 | 0.35% | — | 8.19 | Uncontrolled Recursion (CWE-674) in Elasticsearch can lead to a denial of service via Excessive Allocation (CAPEC-130). … | Jul 1, 2026 |
| CVE-2025-68390 | MEDIUM | 4.9 | 0.34% | — | 8.18 | Allocation of Resources Without Limits or Throttling (CWE-770) in Elasticsearch can allow an authenticated user with sna… | Dec 18, 2025 |
| CVE-2025-68390 | MEDIUM | 4.9 | 0.34% | — | 8.17 | Allocation of Resources Without Limits or Throttling (CWE-770) in Elasticsearch can allow an authenticated user with sna… | Dec 18, 2025 |
| CVE-2025-68390 | MEDIUM | 4.9 | 0.34% | — | 8.19 | Allocation of Resources Without Limits or Throttling (CWE-770) in Elasticsearch can allow an authenticated user with sna… | Dec 18, 2025 |
| CVE-2025-68390 | MEDIUM | 4.9 | 0.34% | — | 8.16 | Allocation of Resources Without Limits or Throttling (CWE-770) in Elasticsearch can allow an authenticated user with sna… | Dec 18, 2025 |
| CVE-2025-68384 | MEDIUM | 6.5 | 0.28% | — | 8.16 | Allocation of Resources Without Limits or Throttling (CWE-770) in Elasticsearch can allow a low-privileged authenticated… | Dec 18, 2025 |
| CVE-2025-68384 | MEDIUM | 6.5 | 0.28% | — | 8.17 | Allocation of Resources Without Limits or Throttling (CWE-770) in Elasticsearch can allow a low-privileged authenticated… | Dec 18, 2025 |
| CVE-2025-68384 | MEDIUM | 6.5 | 0.28% | — | 8.18 | Allocation of Resources Without Limits or Throttling (CWE-770) in Elasticsearch can allow a low-privileged authenticated… | Dec 18, 2025 |
| CVE-2025-68384 | MEDIUM | 6.5 | 0.28% | — | 8.19 | Allocation of Resources Without Limits or Throttling (CWE-770) in Elasticsearch can allow a low-privileged authenticated… | Dec 18, 2025 |
| CVE-2025-37731 | MEDIUM | 6.8 | 0.16% | — | 8.18 | Improper Authentication in Elasticsearch PKI realm can lead to user impersonation via specially crafted client certifica… | Dec 15, 2025 |
| CVE-2025-37731 | MEDIUM | 6.8 | 0.16% | — | 8.19 | Improper Authentication in Elasticsearch PKI realm can lead to user impersonation via specially crafted client certifica… | Dec 15, 2025 |
| CVE-2025-37731 | MEDIUM | 6.8 | 0.16% | — | 8.17 | Improper Authentication in Elasticsearch PKI realm can lead to user impersonation via specially crafted client certifica… | Dec 15, 2025 |
| CVE-2025-37731 | MEDIUM | 6.8 | 0.16% | — | 8.16 | Improper Authentication in Elasticsearch PKI realm can lead to user impersonation via specially crafted client certifica… | Dec 15, 2025 |
Elasticsearch 8.x will reach end of life — migrate to Elasticsearch 9.x
Elasticsearch 9.x is the next major release. Plan your upgrade before Elasticsearch 8.x stops receiving security patches.
Frequently asked questions
Is Elasticsearch 8 end of life?
Partially. Some Elasticsearch 8.x releases have reached EOL. Check the version table above for the exact status of each sub-release.
What CVEs affect Elasticsearch 8?
There are 20 CVEs tracked for Elasticsearch 8.x. See the full list above with CVSS and EPSS scores.
What is the latest Elasticsearch 8 version?
The latest Elasticsearch 8.x patch release is 8.19.19, released on July 15, 2026. Always run the latest patch to benefit from all security fixes.
How to migrate from Elasticsearch 8 to Elasticsearch 9?
To migrate from Elasticsearch 8 to Elasticsearch 9: (1) review the official Elasticsearch 9 migration guide for breaking changes, (2) update dependencies and configuration accordingly, (3) test thoroughly in a staging environment, (4) deploy with a rollback plan. Starting early gives you time to resolve compatibility issues before your current version reaches end of life.
Is it safe to run Elasticsearch 8 in production?
Elasticsearch 8 is still supported and safe for production use until July 15, 2027. Ensure you are running the latest patch version (8.19.19) to have all security fixes applied.
Data sourced from endoflife.date · CVE data from NVD · EPSS from FIRST.org · KEV from CISA
