Elasticsearch 8.x — End of Life

Active Medium risk
EOL: Jul 15, 2027in 356d4 releases in this series20 CVEs

Elasticsearch 8.x — All releases

VersionReleasedActive supportEOL dateLatest patchStatusAlert me
8.19Jul 23, 2025Jul 15, 20278.19.19Active
8.18Apr 10, 2025Oct 21, 20258.18.8EOL
8.17Dec 11, 2024Aug 5, 20258.17.10EOL
8.16Nov 8, 2024Apr 15, 20258.16.6EOL

CVEs affecting Elasticsearch 8.x (20)

CVESeverityCVSSEPSSKEVCycleDescriptionPublished
CVE-2026-56149MEDIUM4.90.32%8.16Allocation of Resources Without Limits or Throttling (CWE-770) in Elasticsearch can lead to a denial of service via Exce…Jul 1, 2026
CVE-2026-56149MEDIUM4.90.32%8.17Allocation of Resources Without Limits or Throttling (CWE-770) in Elasticsearch can lead to a denial of service via Exce…Jul 1, 2026
CVE-2026-56149MEDIUM4.90.32%8.19Allocation of Resources Without Limits or Throttling (CWE-770) in Elasticsearch can lead to a denial of service via Exce…Jul 1, 2026
CVE-2026-56149MEDIUM4.90.32%8.18Allocation of Resources Without Limits or Throttling (CWE-770) in Elasticsearch can lead to a denial of service via Exce…Jul 1, 2026
CVE-2026-56148MEDIUM6.50.35%8.16Uncontrolled Recursion (CWE-674) in Elasticsearch can lead to a denial of service via Excessive Allocation (CAPEC-130). …Jul 1, 2026
CVE-2026-56148MEDIUM6.50.35%8.18Uncontrolled Recursion (CWE-674) in Elasticsearch can lead to a denial of service via Excessive Allocation (CAPEC-130). …Jul 1, 2026
CVE-2026-56148MEDIUM6.50.35%8.17Uncontrolled Recursion (CWE-674) in Elasticsearch can lead to a denial of service via Excessive Allocation (CAPEC-130). …Jul 1, 2026
CVE-2026-56148MEDIUM6.50.35%8.19Uncontrolled Recursion (CWE-674) in Elasticsearch can lead to a denial of service via Excessive Allocation (CAPEC-130). …Jul 1, 2026
CVE-2025-68390MEDIUM4.90.34%8.18Allocation of Resources Without Limits or Throttling (CWE-770) in Elasticsearch can allow an authenticated user with sna…Dec 18, 2025
CVE-2025-68390MEDIUM4.90.34%8.17Allocation of Resources Without Limits or Throttling (CWE-770) in Elasticsearch can allow an authenticated user with sna…Dec 18, 2025
CVE-2025-68390MEDIUM4.90.34%8.19Allocation of Resources Without Limits or Throttling (CWE-770) in Elasticsearch can allow an authenticated user with sna…Dec 18, 2025
CVE-2025-68390MEDIUM4.90.34%8.16Allocation of Resources Without Limits or Throttling (CWE-770) in Elasticsearch can allow an authenticated user with sna…Dec 18, 2025
CVE-2025-68384MEDIUM6.50.28%8.16Allocation of Resources Without Limits or Throttling (CWE-770) in Elasticsearch can allow a low-privileged authenticated…Dec 18, 2025
CVE-2025-68384MEDIUM6.50.28%8.17Allocation of Resources Without Limits or Throttling (CWE-770) in Elasticsearch can allow a low-privileged authenticated…Dec 18, 2025
CVE-2025-68384MEDIUM6.50.28%8.18Allocation of Resources Without Limits or Throttling (CWE-770) in Elasticsearch can allow a low-privileged authenticated…Dec 18, 2025
CVE-2025-68384MEDIUM6.50.28%8.19Allocation of Resources Without Limits or Throttling (CWE-770) in Elasticsearch can allow a low-privileged authenticated…Dec 18, 2025
CVE-2025-37731MEDIUM6.80.16%8.18Improper Authentication in Elasticsearch PKI realm can lead to user impersonation via specially crafted client certifica…Dec 15, 2025
CVE-2025-37731MEDIUM6.80.16%8.19Improper Authentication in Elasticsearch PKI realm can lead to user impersonation via specially crafted client certifica…Dec 15, 2025
CVE-2025-37731MEDIUM6.80.16%8.17Improper Authentication in Elasticsearch PKI realm can lead to user impersonation via specially crafted client certifica…Dec 15, 2025
CVE-2025-37731MEDIUM6.80.16%8.16Improper Authentication in Elasticsearch PKI realm can lead to user impersonation via specially crafted client certifica…Dec 15, 2025

Elasticsearch 8.x will reach end of life — migrate to Elasticsearch 9.x

Elasticsearch 9.x is the next major release. Plan your upgrade before Elasticsearch 8.x stops receiving security patches.

See Elasticsearch 9.x

Frequently asked questions

Is Elasticsearch 8 end of life?

Partially. Some Elasticsearch 8.x releases have reached EOL. Check the version table above for the exact status of each sub-release.

What CVEs affect Elasticsearch 8?

There are 20 CVEs tracked for Elasticsearch 8.x. See the full list above with CVSS and EPSS scores.

What is the latest Elasticsearch 8 version?

The latest Elasticsearch 8.x patch release is 8.19.19, released on July 15, 2026. Always run the latest patch to benefit from all security fixes.

How to migrate from Elasticsearch 8 to Elasticsearch 9?

To migrate from Elasticsearch 8 to Elasticsearch 9: (1) review the official Elasticsearch 9 migration guide for breaking changes, (2) update dependencies and configuration accordingly, (3) test thoroughly in a staging environment, (4) deploy with a rollback plan. Starting early gives you time to resolve compatibility issues before your current version reaches end of life.

Is it safe to run Elasticsearch 8 in production?

Elasticsearch 8 is still supported and safe for production use until July 15, 2027. Ensure you are running the latest patch version (8.19.19) to have all security fixes applied.

Data sourced from endoflife.date · CVE data from NVD · EPSS from FIRST.org · KEV from CISA