Elasticsearch 9.x — End of Life
Active High risk6 releases in this series106 CVEs
Elasticsearch 9.x — All releases
| Version | Released | Active support | EOL date | Latest patch | Status | Alert me |
|---|---|---|---|---|---|---|
| 9.5 | Aug 4, 2026 | — | No | 9.5.3 | Active | |
| 9.4 | May 5, 2026 | — | No | 9.4.6 | Active | |
| 9.3 | Feb 3, 2026 | — | Aug 4, 2026 | 9.3.8 | EOL | |
| 9.2 | Oct 23, 2025 | — | May 5, 2026 | 9.2.8 | EOL | |
| 9.1 | Jul 29, 2025 | — | Feb 3, 2026 | 9.1.10 | EOL | |
| 9.0 | Apr 15, 2025 | — | Oct 23, 2025 | 9.0.8 | EOL |
CVEs affecting Elasticsearch 9.x (106)
| CVE | Severity | CVSS | EPSS | KEV | Cycle | Description | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-56143 | MEDIUM | 4.9 | 0.31% | — | 9.0 | Allocation of Resources Without Limits or Throttling (CWE-770) in Elasticsearch can lead to a denial of service via Exce… | Sep 1, 2026 |
| CVE-2026-56143 | MEDIUM | 4.9 | 0.31% | — | 9.3 | Allocation of Resources Without Limits or Throttling (CWE-770) in Elasticsearch can lead to a denial of service via Exce… | Sep 1, 2026 |
| CVE-2026-56143 | MEDIUM | 4.9 | 0.31% | — | 9.1 | Allocation of Resources Without Limits or Throttling (CWE-770) in Elasticsearch can lead to a denial of service via Exce… | Sep 1, 2026 |
| CVE-2026-56143 | MEDIUM | 4.9 | 0.31% | — | 9.2 | Allocation of Resources Without Limits or Throttling (CWE-770) in Elasticsearch can lead to a denial of service via Exce… | Sep 1, 2026 |
| CVE-2026-72687 | MEDIUM | 6.5 | 0.29% | — | 9.3 | A flaw in Elasticsearch allows a low-privileged authenticated user to submit a single small request containing a forged … | Aug 13, 2026 |
| CVE-2026-72687 | MEDIUM | 6.5 | 0.29% | — | 9.1 | A flaw in Elasticsearch allows a low-privileged authenticated user to submit a single small request containing a forged … | Aug 13, 2026 |
| CVE-2026-72687 | MEDIUM | 6.5 | 0.29% | — | 9.4 | A flaw in Elasticsearch allows a low-privileged authenticated user to submit a single small request containing a forged … | Aug 13, 2026 |
| CVE-2026-72687 | MEDIUM | 6.5 | 0.29% | — | 9.2 | A flaw in Elasticsearch allows a low-privileged authenticated user to submit a single small request containing a forged … | Aug 13, 2026 |
| CVE-2026-72687 | MEDIUM | 6.5 | 0.29% | — | 9.5 | A flaw in Elasticsearch allows a low-privileged authenticated user to submit a single small request containing a forged … | Aug 13, 2026 |
| CVE-2026-72687 | MEDIUM | 6.5 | 0.29% | — | 9.0 | A flaw in Elasticsearch allows a low-privileged authenticated user to submit a single small request containing a forged … | Aug 13, 2026 |
| CVE-2026-72686 | MEDIUM | 6.5 | 0.36% | — | 9.3 | A flaw in Elasticsearch allows a low-privileged authenticated user to submit a single request containing a crafted user-… | Aug 13, 2026 |
| CVE-2026-72686 | MEDIUM | 6.5 | 0.36% | — | 9.4 | A flaw in Elasticsearch allows a low-privileged authenticated user to submit a single request containing a crafted user-… | Aug 13, 2026 |
| CVE-2026-72686 | MEDIUM | 6.5 | 0.36% | — | 9.1 | A flaw in Elasticsearch allows a low-privileged authenticated user to submit a single request containing a crafted user-… | Aug 13, 2026 |
| CVE-2026-72686 | MEDIUM | 6.5 | 0.36% | — | 9.0 | A flaw in Elasticsearch allows a low-privileged authenticated user to submit a single request containing a crafted user-… | Aug 13, 2026 |
| CVE-2026-72686 | MEDIUM | 6.5 | 0.36% | — | 9.2 | A flaw in Elasticsearch allows a low-privileged authenticated user to submit a single request containing a crafted user-… | Aug 13, 2026 |
| CVE-2026-72686 | MEDIUM | 6.5 | 0.36% | — | 9.5 | A flaw in Elasticsearch allows a low-privileged authenticated user to submit a single request containing a crafted user-… | Aug 13, 2026 |
| CVE-2026-72685 | MEDIUM | 4.3 | 0.26% | — | 9.4 | A flaw in Elasticsearch allows a low-privileged authenticated user who can index documents to submit a single small docu… | Aug 13, 2026 |
| CVE-2026-72685 | MEDIUM | 4.3 | 0.26% | — | 9.0 | A flaw in Elasticsearch allows a low-privileged authenticated user who can index documents to submit a single small docu… | Aug 13, 2026 |
| CVE-2026-72685 | MEDIUM | 4.3 | 0.26% | — | 9.2 | A flaw in Elasticsearch allows a low-privileged authenticated user who can index documents to submit a single small docu… | Aug 13, 2026 |
| CVE-2026-72685 | MEDIUM | 4.3 | 0.26% | — | 9.3 | A flaw in Elasticsearch allows a low-privileged authenticated user who can index documents to submit a single small docu… | Aug 13, 2026 |
| CVE-2026-72685 | MEDIUM | 4.3 | 0.26% | — | 9.1 | A flaw in Elasticsearch allows a low-privileged authenticated user who can index documents to submit a single small docu… | Aug 13, 2026 |
| CVE-2026-72684 | MEDIUM | 6.5 | 0.29% | — | 9.2 | A flaw in Elasticsearch allows an authenticated user holding only read privileges to submit a small search request conta… | Aug 13, 2026 |
| CVE-2026-72684 | MEDIUM | 6.5 | 0.29% | — | 9.3 | A flaw in Elasticsearch allows an authenticated user holding only read privileges to submit a small search request conta… | Aug 13, 2026 |
| CVE-2026-72684 | MEDIUM | 6.5 | 0.29% | — | 9.0 | A flaw in Elasticsearch allows an authenticated user holding only read privileges to submit a small search request conta… | Aug 13, 2026 |
| CVE-2026-72684 | MEDIUM | 6.5 | 0.29% | — | 9.1 | A flaw in Elasticsearch allows an authenticated user holding only read privileges to submit a small search request conta… | Aug 13, 2026 |
| CVE-2026-72684 | MEDIUM | 6.5 | 0.29% | — | 9.4 | A flaw in Elasticsearch allows an authenticated user holding only read privileges to submit a small search request conta… | Aug 13, 2026 |
| CVE-2026-72683 | MEDIUM | 6.5 | 0.36% | — | 9.3 | A flaw in Elasticsearch allows an authenticated user with the privileges required to invoke the simulate pipeline API en… | Aug 13, 2026 |
| CVE-2026-72683 | MEDIUM | 6.5 | 0.36% | — | 9.4 | A flaw in Elasticsearch allows an authenticated user with the privileges required to invoke the simulate pipeline API en… | Aug 13, 2026 |
| CVE-2026-72679 | MEDIUM | 6.5 | 0.33% | — | 9.4 | Elasticsearch does not apply its configurable input length restriction to a user-supplied pattern accepted by an interva… | Aug 13, 2026 |
| CVE-2026-72679 | MEDIUM | 6.5 | 0.33% | — | 9.0 | Elasticsearch does not apply its configurable input length restriction to a user-supplied pattern accepted by an interva… | Aug 13, 2026 |
| CVE-2026-72679 | MEDIUM | 6.5 | 0.33% | — | 9.3 | Elasticsearch does not apply its configurable input length restriction to a user-supplied pattern accepted by an interva… | Aug 13, 2026 |
| CVE-2026-72679 | MEDIUM | 6.5 | 0.33% | — | 9.1 | Elasticsearch does not apply its configurable input length restriction to a user-supplied pattern accepted by an interva… | Aug 13, 2026 |
| CVE-2026-72679 | MEDIUM | 6.5 | 0.33% | — | 9.2 | Elasticsearch does not apply its configurable input length restriction to a user-supplied pattern accepted by an interva… | Aug 13, 2026 |
| CVE-2026-72678 | MEDIUM | 6.5 | 0.29% | — | 9.4 | Elasticsearch does not validate a size value taken from a user-supplied input before that value is used to reserve memor… | Aug 13, 2026 |
| CVE-2026-72678 | MEDIUM | 6.5 | 0.29% | — | 9.5 | Elasticsearch does not validate a size value taken from a user-supplied input before that value is used to reserve memor… | Aug 13, 2026 |
| CVE-2026-72647 | MEDIUM | 6.5 | 0.29% | — | 9.1 | Uncontrolled Recursion (CWE-674) in Elasticsearch can lead to denial of service via Serialized Data with Nested Payloads… | Aug 13, 2026 |
| CVE-2026-72647 | MEDIUM | 6.5 | 0.29% | — | 9.0 | Uncontrolled Recursion (CWE-674) in Elasticsearch can lead to denial of service via Serialized Data with Nested Payloads… | Aug 13, 2026 |
| CVE-2026-72647 | MEDIUM | 6.5 | 0.29% | — | 9.4 | Uncontrolled Recursion (CWE-674) in Elasticsearch can lead to denial of service via Serialized Data with Nested Payloads… | Aug 13, 2026 |
| CVE-2026-72647 | MEDIUM | 6.5 | 0.29% | — | 9.3 | Uncontrolled Recursion (CWE-674) in Elasticsearch can lead to denial of service via Serialized Data with Nested Payloads… | Aug 13, 2026 |
| CVE-2026-72647 | MEDIUM | 6.5 | 0.29% | — | 9.2 | Uncontrolled Recursion (CWE-674) in Elasticsearch can lead to denial of service via Serialized Data with Nested Payloads… | Aug 13, 2026 |
| CVE-2026-72645 | MEDIUM | 6.5 | 0.29% | — | 9.4 | Memory Allocation with Excessive Size Value (CWE-789) in Elasticsearch can lead to denial of service via Excessive Alloc… | Aug 13, 2026 |
| CVE-2026-72645 | MEDIUM | 6.5 | 0.29% | — | 9.0 | Memory Allocation with Excessive Size Value (CWE-789) in Elasticsearch can lead to denial of service via Excessive Alloc… | Aug 13, 2026 |
| CVE-2026-72645 | MEDIUM | 6.5 | 0.29% | — | 9.2 | Memory Allocation with Excessive Size Value (CWE-789) in Elasticsearch can lead to denial of service via Excessive Alloc… | Aug 13, 2026 |
| CVE-2026-72645 | MEDIUM | 6.5 | 0.29% | — | 9.5 | Memory Allocation with Excessive Size Value (CWE-789) in Elasticsearch can lead to denial of service via Excessive Alloc… | Aug 13, 2026 |
| CVE-2026-72645 | MEDIUM | 6.5 | 0.29% | — | 9.3 | Memory Allocation with Excessive Size Value (CWE-789) in Elasticsearch can lead to denial of service via Excessive Alloc… | Aug 13, 2026 |
| CVE-2026-72645 | MEDIUM | 6.5 | 0.29% | — | 9.1 | Memory Allocation with Excessive Size Value (CWE-789) in Elasticsearch can lead to denial of service via Excessive Alloc… | Aug 13, 2026 |
| CVE-2026-72642 | HIGH | 8.8 | 0.33% | — | 9.5 | The native inference process that Elasticsearch uses to evaluate uploaded machine learning models accepts a model operat… | Aug 13, 2026 |
| CVE-2026-72642 | HIGH | 8.8 | 0.33% | — | 9.4 | The native inference process that Elasticsearch uses to evaluate uploaded machine learning models accepts a model operat… | Aug 13, 2026 |
| CVE-2026-72639 | MEDIUM | 6.5 | 0.29% | — | 9.5 | Elasticsearch does not enforce an upper bound on a user-supplied count accepted by a search highlighting option, and the… | Aug 13, 2026 |
| CVE-2026-72639 | MEDIUM | 6.5 | 0.29% | — | 9.4 | Elasticsearch does not enforce an upper bound on a user-supplied count accepted by a search highlighting option, and the… | Aug 13, 2026 |
| CVE-2026-72639 | MEDIUM | 6.5 | 0.29% | — | 9.3 | Elasticsearch does not enforce an upper bound on a user-supplied count accepted by a search highlighting option, and the… | Aug 13, 2026 |
| CVE-2026-72638 | MEDIUM | 6.5 | 0.29% | — | 9.3 | Uncontrolled Recursion (CWE-674) in Elasticsearch can lead to denial of service via Input Data Manipulation (CAPEC-153).… | Aug 13, 2026 |
| CVE-2026-72638 | MEDIUM | 6.5 | 0.29% | — | 9.2 | Uncontrolled Recursion (CWE-674) in Elasticsearch can lead to denial of service via Input Data Manipulation (CAPEC-153).… | Aug 13, 2026 |
| CVE-2026-72638 | MEDIUM | 6.5 | 0.29% | — | 9.1 | Uncontrolled Recursion (CWE-674) in Elasticsearch can lead to denial of service via Input Data Manipulation (CAPEC-153).… | Aug 13, 2026 |
| CVE-2026-72638 | MEDIUM | 6.5 | 0.29% | — | 9.4 | Uncontrolled Recursion (CWE-674) in Elasticsearch can lead to denial of service via Input Data Manipulation (CAPEC-153).… | Aug 13, 2026 |
| CVE-2026-72638 | MEDIUM | 6.5 | 0.29% | — | 9.0 | Uncontrolled Recursion (CWE-674) in Elasticsearch can lead to denial of service via Input Data Manipulation (CAPEC-153).… | Aug 13, 2026 |
| CVE-2026-72636 | MEDIUM | 6.5 | 0.30% | — | 9.0 | Uncontrolled Recursion (CWE-674) in the Elasticsearch wildcard matching helper can lead to a denial of service via Exces… | Aug 13, 2026 |
| CVE-2026-72636 | MEDIUM | 6.5 | 0.30% | — | 9.4 | Uncontrolled Recursion (CWE-674) in the Elasticsearch wildcard matching helper can lead to a denial of service via Exces… | Aug 13, 2026 |
| CVE-2026-72636 | MEDIUM | 6.5 | 0.30% | — | 9.2 | Uncontrolled Recursion (CWE-674) in the Elasticsearch wildcard matching helper can lead to a denial of service via Exces… | Aug 13, 2026 |
| CVE-2026-72636 | MEDIUM | 6.5 | 0.30% | — | 9.1 | Uncontrolled Recursion (CWE-674) in the Elasticsearch wildcard matching helper can lead to a denial of service via Exces… | Aug 13, 2026 |
| CVE-2026-72636 | MEDIUM | 6.5 | 0.30% | — | 9.3 | Uncontrolled Recursion (CWE-674) in the Elasticsearch wildcard matching helper can lead to a denial of service via Exces… | Aug 13, 2026 |
| CVE-2026-63263 | MEDIUM | 6.5 | 0.23% | — | 9.1 | Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead to denial of service via Exponential Data Expansio… | Jul 22, 2026 |
| CVE-2026-63263 | MEDIUM | 6.5 | 0.23% | — | 9.0 | Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead to denial of service via Exponential Data Expansio… | Jul 22, 2026 |
| CVE-2026-63263 | MEDIUM | 6.5 | 0.23% | — | 9.4 | Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead to denial of service via Exponential Data Expansio… | Jul 22, 2026 |
| CVE-2026-63263 | MEDIUM | 6.5 | 0.23% | — | 9.3 | Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead to denial of service via Exponential Data Expansio… | Jul 22, 2026 |
| CVE-2026-63263 | MEDIUM | 6.5 | 0.23% | — | 9.2 | Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead to denial of service via Exponential Data Expansio… | Jul 22, 2026 |
| CVE-2026-63144 | MEDIUM | 6.5 | 0.23% | — | 9.3 | Uncontrolled Recursion (CWE-674) in Elasticsearch can lead to denial of service via a specially crafted search request s… | Jul 21, 2026 |
| CVE-2026-63144 | MEDIUM | 6.5 | 0.23% | — | 9.4 | Uncontrolled Recursion (CWE-674) in Elasticsearch can lead to denial of service via a specially crafted search request s… | Jul 21, 2026 |
| CVE-2026-63140 | MEDIUM | 6.5 | 0.23% | — | 9.3 | Reachable Assertion (CWE-617) in Elasticsearch can lead to denial of service via Input Data Manipulation (CAPEC-153). A … | Jul 21, 2026 |
| CVE-2026-63140 | MEDIUM | 6.5 | 0.23% | — | 9.0 | Reachable Assertion (CWE-617) in Elasticsearch can lead to denial of service via Input Data Manipulation (CAPEC-153). A … | Jul 21, 2026 |
| CVE-2026-63140 | MEDIUM | 6.5 | 0.23% | — | 9.2 | Reachable Assertion (CWE-617) in Elasticsearch can lead to denial of service via Input Data Manipulation (CAPEC-153). A … | Jul 21, 2026 |
| CVE-2026-63140 | MEDIUM | 6.5 | 0.23% | — | 9.1 | Reachable Assertion (CWE-617) in Elasticsearch can lead to denial of service via Input Data Manipulation (CAPEC-153). A … | Jul 21, 2026 |
| CVE-2026-63140 | MEDIUM | 6.5 | 0.23% | — | 9.4 | Reachable Assertion (CWE-617) in Elasticsearch can lead to denial of service via Input Data Manipulation (CAPEC-153). A … | Jul 21, 2026 |
| CVE-2026-63136 | MEDIUM | 6.5 | 0.23% | — | 9.1 | Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead to denial of service via Excessive Allocation (CAP… | Jul 21, 2026 |
| CVE-2026-63136 | MEDIUM | 6.5 | 0.23% | — | 9.0 | Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead to denial of service via Excessive Allocation (CAP… | Jul 21, 2026 |
| CVE-2026-63136 | MEDIUM | 6.5 | 0.23% | — | 9.3 | Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead to denial of service via Excessive Allocation (CAP… | Jul 21, 2026 |
| CVE-2026-63136 | MEDIUM | 6.5 | 0.23% | — | 9.2 | Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead to denial of service via Excessive Allocation (CAP… | Jul 21, 2026 |
| CVE-2026-56145 | MEDIUM | 6.5 | 0.29% | — | 9.4 | Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead to denial of service via Excessive Allocation (CAP… | Jul 21, 2026 |
| CVE-2026-56145 | MEDIUM | 6.5 | 0.29% | — | 9.1 | Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead to denial of service via Excessive Allocation (CAP… | Jul 21, 2026 |
| CVE-2026-56145 | MEDIUM | 6.5 | 0.29% | — | 9.3 | Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead to denial of service via Excessive Allocation (CAP… | Jul 21, 2026 |
| CVE-2026-56145 | MEDIUM | 6.5 | 0.29% | — | 9.0 | Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead to denial of service via Excessive Allocation (CAP… | Jul 21, 2026 |
| CVE-2026-56145 | MEDIUM | 6.5 | 0.29% | — | 9.2 | Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead to denial of service via Excessive Allocation (CAP… | Jul 21, 2026 |
| CVE-2026-56144 | MEDIUM | 5.3 | 0.23% | — | 9.0 | Incorrect Authorization (CWE-863) in Elasticsearch can allow an authenticated user with limited index privileges to expl… | Jul 21, 2026 |
| CVE-2026-56144 | MEDIUM | 5.3 | 0.23% | — | 9.3 | Incorrect Authorization (CWE-863) in Elasticsearch can allow an authenticated user with limited index privileges to expl… | Jul 21, 2026 |
| CVE-2026-56144 | MEDIUM | 5.3 | 0.23% | — | 9.4 | Incorrect Authorization (CWE-863) in Elasticsearch can allow an authenticated user with limited index privileges to expl… | Jul 21, 2026 |
| CVE-2026-56144 | MEDIUM | 5.3 | 0.23% | — | 9.1 | Incorrect Authorization (CWE-863) in Elasticsearch can allow an authenticated user with limited index privileges to expl… | Jul 21, 2026 |
| CVE-2026-56144 | MEDIUM | 5.3 | 0.23% | — | 9.2 | Incorrect Authorization (CWE-863) in Elasticsearch can allow an authenticated user with limited index privileges to expl… | Jul 21, 2026 |
| CVE-2026-56149 | MEDIUM | 4.9 | 0.50% | — | 9.2 | Allocation of Resources Without Limits or Throttling (CWE-770) in Elasticsearch can lead to a denial of service via Exce… | Jul 1, 2026 |
| CVE-2026-56149 | MEDIUM | 4.9 | 0.50% | — | 9.4 | Allocation of Resources Without Limits or Throttling (CWE-770) in Elasticsearch can lead to a denial of service via Exce… | Jul 1, 2026 |
| CVE-2026-56149 | MEDIUM | 4.9 | 0.50% | — | 9.3 | Allocation of Resources Without Limits or Throttling (CWE-770) in Elasticsearch can lead to a denial of service via Exce… | Jul 1, 2026 |
| CVE-2026-56149 | MEDIUM | 4.9 | 0.50% | — | 9.1 | Allocation of Resources Without Limits or Throttling (CWE-770) in Elasticsearch can lead to a denial of service via Exce… | Jul 1, 2026 |
| CVE-2026-56149 | MEDIUM | 4.9 | 0.50% | — | 9.0 | Allocation of Resources Without Limits or Throttling (CWE-770) in Elasticsearch can lead to a denial of service via Exce… | Jul 1, 2026 |
| CVE-2026-56148 | MEDIUM | 6.5 | 0.47% | — | 9.0 | Uncontrolled Recursion (CWE-674) in Elasticsearch can lead to a denial of service via Excessive Allocation (CAPEC-130). … | Jul 1, 2026 |
| CVE-2026-56148 | MEDIUM | 6.5 | 0.47% | — | 9.4 | Uncontrolled Recursion (CWE-674) in Elasticsearch can lead to a denial of service via Excessive Allocation (CAPEC-130). … | Jul 1, 2026 |
| CVE-2026-56148 | MEDIUM | 6.5 | 0.47% | — | 9.3 | Uncontrolled Recursion (CWE-674) in Elasticsearch can lead to a denial of service via Excessive Allocation (CAPEC-130). … | Jul 1, 2026 |
| CVE-2026-56148 | MEDIUM | 6.5 | 0.47% | — | 9.2 | Uncontrolled Recursion (CWE-674) in Elasticsearch can lead to a denial of service via Excessive Allocation (CAPEC-130). … | Jul 1, 2026 |
| CVE-2026-56148 | MEDIUM | 6.5 | 0.47% | — | 9.1 | Uncontrolled Recursion (CWE-674) in Elasticsearch can lead to a denial of service via Excessive Allocation (CAPEC-130). … | Jul 1, 2026 |
| CVE-2025-68390 | MEDIUM | 4.9 | 0.37% | — | 9.2 | Allocation of Resources Without Limits or Throttling (CWE-770) in Elasticsearch can allow an authenticated user with sna… | Dec 18, 2025 |
| CVE-2025-68390 | MEDIUM | 4.9 | 0.37% | — | 9.0 | Allocation of Resources Without Limits or Throttling (CWE-770) in Elasticsearch can allow an authenticated user with sna… | Dec 18, 2025 |
| CVE-2025-68390 | MEDIUM | 4.9 | 0.37% | — | 9.1 | Allocation of Resources Without Limits or Throttling (CWE-770) in Elasticsearch can allow an authenticated user with sna… | Dec 18, 2025 |
| CVE-2025-68384 | MEDIUM | 6.5 | 0.31% | — | 9.1 | Allocation of Resources Without Limits or Throttling (CWE-770) in Elasticsearch can allow a low-privileged authenticated… | Dec 18, 2025 |
| CVE-2025-68384 | MEDIUM | 6.5 | 0.31% | — | 9.0 | Allocation of Resources Without Limits or Throttling (CWE-770) in Elasticsearch can allow a low-privileged authenticated… | Dec 18, 2025 |
| CVE-2025-68384 | MEDIUM | 6.5 | 0.31% | — | 9.2 | Allocation of Resources Without Limits or Throttling (CWE-770) in Elasticsearch can allow a low-privileged authenticated… | Dec 18, 2025 |
| CVE-2025-37731 | MEDIUM | 6.8 | 0.19% | — | 9.1 | Improper Authentication in Elasticsearch PKI realm can lead to user impersonation via specially crafted client certifica… | Dec 15, 2025 |
| CVE-2025-37731 | MEDIUM | 6.8 | 0.19% | — | 9.2 | Improper Authentication in Elasticsearch PKI realm can lead to user impersonation via specially crafted client certifica… | Dec 15, 2025 |
| CVE-2025-37731 | MEDIUM | 6.8 | 0.19% | — | 9.0 | Improper Authentication in Elasticsearch PKI realm can lead to user impersonation via specially crafted client certifica… | Dec 15, 2025 |
Frequently asked questions
Is Elasticsearch 9 end of life?
Partially. Some Elasticsearch 9.x releases have reached EOL. Check the version table above for the exact status of each sub-release.
What CVEs affect Elasticsearch 9?
There are 106 CVEs tracked for Elasticsearch 9.x. See the full list above with CVSS and EPSS scores.
What is the latest Elasticsearch 9 version?
The latest Elasticsearch 9.x patch release is 9.5.3, released on September 3, 2026. Always run the latest patch to benefit from all security fixes.
When was Elasticsearch 9 first released?
Elasticsearch 9.0 was initially released on August 4, 2026. See the full version timeline in the table above.
Is it safe to run Elasticsearch 9 in production?
Elasticsearch 9 is still supported and safe for production use. Ensure you are running the latest patch version (9.5.3) to have all security fixes applied.
Data sourced from endoflife.date · CVE data from NVD · EPSS from FIRST.org · KEV from CISA
