Elasticsearch 9.x — End of Life
Active Medium risk5 releases in this series19 CVEs
Elasticsearch 9.x — All releases
| Version | Released | Active support | EOL date | Latest patch | Status | Alert me |
|---|---|---|---|---|---|---|
| 9.4 | May 5, 2026 | — | No | 9.4.4 | Active | |
| 9.3 | Feb 3, 2026 | — | May 26, 2026 | 9.3.8 | EOL | |
| 9.2 | Oct 21, 2025 | — | May 5, 2026 | 9.2.8 | EOL | |
| 9.1 | Jul 23, 2025 | — | Feb 3, 2026 | 9.1.10 | EOL | |
| 9.0 | Apr 8, 2025 | — | Oct 2, 2025 | 9.0.8 | EOL |
CVEs affecting Elasticsearch 9.x (19)
| CVE | Severity | CVSS | EPSS | KEV | Cycle | Description | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-56149 | MEDIUM | 4.9 | 0.32% | — | 9.0 | Allocation of Resources Without Limits or Throttling (CWE-770) in Elasticsearch can lead to a denial of service via Exce… | Jul 1, 2026 |
| CVE-2026-56149 | MEDIUM | 4.9 | 0.32% | — | 9.3 | Allocation of Resources Without Limits or Throttling (CWE-770) in Elasticsearch can lead to a denial of service via Exce… | Jul 1, 2026 |
| CVE-2026-56149 | MEDIUM | 4.9 | 0.32% | — | 9.2 | Allocation of Resources Without Limits or Throttling (CWE-770) in Elasticsearch can lead to a denial of service via Exce… | Jul 1, 2026 |
| CVE-2026-56149 | MEDIUM | 4.9 | 0.32% | — | 9.1 | Allocation of Resources Without Limits or Throttling (CWE-770) in Elasticsearch can lead to a denial of service via Exce… | Jul 1, 2026 |
| CVE-2026-56149 | MEDIUM | 4.9 | 0.32% | — | 9.4 | Allocation of Resources Without Limits or Throttling (CWE-770) in Elasticsearch can lead to a denial of service via Exce… | Jul 1, 2026 |
| CVE-2026-56148 | MEDIUM | 6.5 | 0.35% | — | 9.3 | Uncontrolled Recursion (CWE-674) in Elasticsearch can lead to a denial of service via Excessive Allocation (CAPEC-130). … | Jul 1, 2026 |
| CVE-2026-56148 | MEDIUM | 6.5 | 0.35% | — | 9.4 | Uncontrolled Recursion (CWE-674) in Elasticsearch can lead to a denial of service via Excessive Allocation (CAPEC-130). … | Jul 1, 2026 |
| CVE-2026-56148 | MEDIUM | 6.5 | 0.35% | — | 9.1 | Uncontrolled Recursion (CWE-674) in Elasticsearch can lead to a denial of service via Excessive Allocation (CAPEC-130). … | Jul 1, 2026 |
| CVE-2026-56148 | MEDIUM | 6.5 | 0.35% | — | 9.2 | Uncontrolled Recursion (CWE-674) in Elasticsearch can lead to a denial of service via Excessive Allocation (CAPEC-130). … | Jul 1, 2026 |
| CVE-2026-56148 | MEDIUM | 6.5 | 0.35% | — | 9.0 | Uncontrolled Recursion (CWE-674) in Elasticsearch can lead to a denial of service via Excessive Allocation (CAPEC-130). … | Jul 1, 2026 |
| CVE-2025-68390 | MEDIUM | 4.9 | 0.34% | — | 9.2 | Allocation of Resources Without Limits or Throttling (CWE-770) in Elasticsearch can allow an authenticated user with sna… | Dec 18, 2025 |
| CVE-2025-68390 | MEDIUM | 4.9 | 0.34% | — | 9.1 | Allocation of Resources Without Limits or Throttling (CWE-770) in Elasticsearch can allow an authenticated user with sna… | Dec 18, 2025 |
| CVE-2025-68390 | MEDIUM | 4.9 | 0.34% | — | 9.0 | Allocation of Resources Without Limits or Throttling (CWE-770) in Elasticsearch can allow an authenticated user with sna… | Dec 18, 2025 |
| CVE-2025-68384 | MEDIUM | 6.5 | 0.28% | — | 9.1 | Allocation of Resources Without Limits or Throttling (CWE-770) in Elasticsearch can allow a low-privileged authenticated… | Dec 18, 2025 |
| CVE-2025-68384 | MEDIUM | 6.5 | 0.28% | — | 9.0 | Allocation of Resources Without Limits or Throttling (CWE-770) in Elasticsearch can allow a low-privileged authenticated… | Dec 18, 2025 |
| CVE-2025-68384 | MEDIUM | 6.5 | 0.28% | — | 9.2 | Allocation of Resources Without Limits or Throttling (CWE-770) in Elasticsearch can allow a low-privileged authenticated… | Dec 18, 2025 |
| CVE-2025-37731 | MEDIUM | 6.8 | 0.16% | — | 9.2 | Improper Authentication in Elasticsearch PKI realm can lead to user impersonation via specially crafted client certifica… | Dec 15, 2025 |
| CVE-2025-37731 | MEDIUM | 6.8 | 0.16% | — | 9.0 | Improper Authentication in Elasticsearch PKI realm can lead to user impersonation via specially crafted client certifica… | Dec 15, 2025 |
| CVE-2025-37731 | MEDIUM | 6.8 | 0.16% | — | 9.1 | Improper Authentication in Elasticsearch PKI realm can lead to user impersonation via specially crafted client certifica… | Dec 15, 2025 |
Frequently asked questions
Is Elasticsearch 9 end of life?
Partially. Some Elasticsearch 9.x releases have reached EOL. Check the version table above for the exact status of each sub-release.
What CVEs affect Elasticsearch 9?
There are 19 CVEs tracked for Elasticsearch 9.x. See the full list above with CVSS and EPSS scores.
What is the latest Elasticsearch 9 version?
The latest Elasticsearch 9.x patch release is 9.4.4, released on July 15, 2026. Always run the latest patch to benefit from all security fixes.
When was Elasticsearch 9 first released?
Elasticsearch 9.0 was initially released on May 5, 2026. See the full version timeline in the table above.
Is it safe to run Elasticsearch 9 in production?
Elasticsearch 9 is still supported and safe for production use. Ensure you are running the latest patch version (9.4.4) to have all security fixes applied.
Data sourced from endoflife.date · CVE data from NVD · EPSS from FIRST.org · KEV from CISA
