Elasticsearch 9.x — End of Life

Active High risk
6 releases in this series106 CVEs

Elasticsearch 9.x — All releases

VersionReleasedActive supportEOL dateLatest patchStatusAlert me
9.5Aug 4, 2026No9.5.3Active
9.4May 5, 2026No9.4.6Active
9.3Feb 3, 2026Aug 4, 20269.3.8EOL
9.2Oct 23, 2025May 5, 20269.2.8EOL
9.1Jul 29, 2025Feb 3, 20269.1.10EOL
9.0Apr 15, 2025Oct 23, 20259.0.8EOL

CVEs affecting Elasticsearch 9.x (106)

CVESeverityCVSSEPSSKEVCycleDescriptionPublished
CVE-2026-56143MEDIUM4.90.31%9.0Allocation of Resources Without Limits or Throttling (CWE-770) in Elasticsearch can lead to a denial of service via Exce…Sep 1, 2026
CVE-2026-56143MEDIUM4.90.31%9.3Allocation of Resources Without Limits or Throttling (CWE-770) in Elasticsearch can lead to a denial of service via Exce…Sep 1, 2026
CVE-2026-56143MEDIUM4.90.31%9.1Allocation of Resources Without Limits or Throttling (CWE-770) in Elasticsearch can lead to a denial of service via Exce…Sep 1, 2026
CVE-2026-56143MEDIUM4.90.31%9.2Allocation of Resources Without Limits or Throttling (CWE-770) in Elasticsearch can lead to a denial of service via Exce…Sep 1, 2026
CVE-2026-72687MEDIUM6.50.29%9.3A flaw in Elasticsearch allows a low-privileged authenticated user to submit a single small request containing a forged …Aug 13, 2026
CVE-2026-72687MEDIUM6.50.29%9.1A flaw in Elasticsearch allows a low-privileged authenticated user to submit a single small request containing a forged …Aug 13, 2026
CVE-2026-72687MEDIUM6.50.29%9.4A flaw in Elasticsearch allows a low-privileged authenticated user to submit a single small request containing a forged …Aug 13, 2026
CVE-2026-72687MEDIUM6.50.29%9.2A flaw in Elasticsearch allows a low-privileged authenticated user to submit a single small request containing a forged …Aug 13, 2026
CVE-2026-72687MEDIUM6.50.29%9.5A flaw in Elasticsearch allows a low-privileged authenticated user to submit a single small request containing a forged …Aug 13, 2026
CVE-2026-72687MEDIUM6.50.29%9.0A flaw in Elasticsearch allows a low-privileged authenticated user to submit a single small request containing a forged …Aug 13, 2026
CVE-2026-72686MEDIUM6.50.36%9.3A flaw in Elasticsearch allows a low-privileged authenticated user to submit a single request containing a crafted user-…Aug 13, 2026
CVE-2026-72686MEDIUM6.50.36%9.4A flaw in Elasticsearch allows a low-privileged authenticated user to submit a single request containing a crafted user-…Aug 13, 2026
CVE-2026-72686MEDIUM6.50.36%9.1A flaw in Elasticsearch allows a low-privileged authenticated user to submit a single request containing a crafted user-…Aug 13, 2026
CVE-2026-72686MEDIUM6.50.36%9.0A flaw in Elasticsearch allows a low-privileged authenticated user to submit a single request containing a crafted user-…Aug 13, 2026
CVE-2026-72686MEDIUM6.50.36%9.2A flaw in Elasticsearch allows a low-privileged authenticated user to submit a single request containing a crafted user-…Aug 13, 2026
CVE-2026-72686MEDIUM6.50.36%9.5A flaw in Elasticsearch allows a low-privileged authenticated user to submit a single request containing a crafted user-…Aug 13, 2026
CVE-2026-72685MEDIUM4.30.26%9.4A flaw in Elasticsearch allows a low-privileged authenticated user who can index documents to submit a single small docu…Aug 13, 2026
CVE-2026-72685MEDIUM4.30.26%9.0A flaw in Elasticsearch allows a low-privileged authenticated user who can index documents to submit a single small docu…Aug 13, 2026
CVE-2026-72685MEDIUM4.30.26%9.2A flaw in Elasticsearch allows a low-privileged authenticated user who can index documents to submit a single small docu…Aug 13, 2026
CVE-2026-72685MEDIUM4.30.26%9.3A flaw in Elasticsearch allows a low-privileged authenticated user who can index documents to submit a single small docu…Aug 13, 2026
CVE-2026-72685MEDIUM4.30.26%9.1A flaw in Elasticsearch allows a low-privileged authenticated user who can index documents to submit a single small docu…Aug 13, 2026
CVE-2026-72684MEDIUM6.50.29%9.2A flaw in Elasticsearch allows an authenticated user holding only read privileges to submit a small search request conta…Aug 13, 2026
CVE-2026-72684MEDIUM6.50.29%9.3A flaw in Elasticsearch allows an authenticated user holding only read privileges to submit a small search request conta…Aug 13, 2026
CVE-2026-72684MEDIUM6.50.29%9.0A flaw in Elasticsearch allows an authenticated user holding only read privileges to submit a small search request conta…Aug 13, 2026
CVE-2026-72684MEDIUM6.50.29%9.1A flaw in Elasticsearch allows an authenticated user holding only read privileges to submit a small search request conta…Aug 13, 2026
CVE-2026-72684MEDIUM6.50.29%9.4A flaw in Elasticsearch allows an authenticated user holding only read privileges to submit a small search request conta…Aug 13, 2026
CVE-2026-72683MEDIUM6.50.36%9.3A flaw in Elasticsearch allows an authenticated user with the privileges required to invoke the simulate pipeline API en…Aug 13, 2026
CVE-2026-72683MEDIUM6.50.36%9.4A flaw in Elasticsearch allows an authenticated user with the privileges required to invoke the simulate pipeline API en…Aug 13, 2026
CVE-2026-72679MEDIUM6.50.33%9.4Elasticsearch does not apply its configurable input length restriction to a user-supplied pattern accepted by an interva…Aug 13, 2026
CVE-2026-72679MEDIUM6.50.33%9.0Elasticsearch does not apply its configurable input length restriction to a user-supplied pattern accepted by an interva…Aug 13, 2026
CVE-2026-72679MEDIUM6.50.33%9.3Elasticsearch does not apply its configurable input length restriction to a user-supplied pattern accepted by an interva…Aug 13, 2026
CVE-2026-72679MEDIUM6.50.33%9.1Elasticsearch does not apply its configurable input length restriction to a user-supplied pattern accepted by an interva…Aug 13, 2026
CVE-2026-72679MEDIUM6.50.33%9.2Elasticsearch does not apply its configurable input length restriction to a user-supplied pattern accepted by an interva…Aug 13, 2026
CVE-2026-72678MEDIUM6.50.29%9.4Elasticsearch does not validate a size value taken from a user-supplied input before that value is used to reserve memor…Aug 13, 2026
CVE-2026-72678MEDIUM6.50.29%9.5Elasticsearch does not validate a size value taken from a user-supplied input before that value is used to reserve memor…Aug 13, 2026
CVE-2026-72647MEDIUM6.50.29%9.1Uncontrolled Recursion (CWE-674) in Elasticsearch can lead to denial of service via Serialized Data with Nested Payloads…Aug 13, 2026
CVE-2026-72647MEDIUM6.50.29%9.0Uncontrolled Recursion (CWE-674) in Elasticsearch can lead to denial of service via Serialized Data with Nested Payloads…Aug 13, 2026
CVE-2026-72647MEDIUM6.50.29%9.4Uncontrolled Recursion (CWE-674) in Elasticsearch can lead to denial of service via Serialized Data with Nested Payloads…Aug 13, 2026
CVE-2026-72647MEDIUM6.50.29%9.3Uncontrolled Recursion (CWE-674) in Elasticsearch can lead to denial of service via Serialized Data with Nested Payloads…Aug 13, 2026
CVE-2026-72647MEDIUM6.50.29%9.2Uncontrolled Recursion (CWE-674) in Elasticsearch can lead to denial of service via Serialized Data with Nested Payloads…Aug 13, 2026
CVE-2026-72645MEDIUM6.50.29%9.4Memory Allocation with Excessive Size Value (CWE-789) in Elasticsearch can lead to denial of service via Excessive Alloc…Aug 13, 2026
CVE-2026-72645MEDIUM6.50.29%9.0Memory Allocation with Excessive Size Value (CWE-789) in Elasticsearch can lead to denial of service via Excessive Alloc…Aug 13, 2026
CVE-2026-72645MEDIUM6.50.29%9.2Memory Allocation with Excessive Size Value (CWE-789) in Elasticsearch can lead to denial of service via Excessive Alloc…Aug 13, 2026
CVE-2026-72645MEDIUM6.50.29%9.5Memory Allocation with Excessive Size Value (CWE-789) in Elasticsearch can lead to denial of service via Excessive Alloc…Aug 13, 2026
CVE-2026-72645MEDIUM6.50.29%9.3Memory Allocation with Excessive Size Value (CWE-789) in Elasticsearch can lead to denial of service via Excessive Alloc…Aug 13, 2026
CVE-2026-72645MEDIUM6.50.29%9.1Memory Allocation with Excessive Size Value (CWE-789) in Elasticsearch can lead to denial of service via Excessive Alloc…Aug 13, 2026
CVE-2026-72642HIGH8.80.33%9.5The native inference process that Elasticsearch uses to evaluate uploaded machine learning models accepts a model operat…Aug 13, 2026
CVE-2026-72642HIGH8.80.33%9.4The native inference process that Elasticsearch uses to evaluate uploaded machine learning models accepts a model operat…Aug 13, 2026
CVE-2026-72639MEDIUM6.50.29%9.5Elasticsearch does not enforce an upper bound on a user-supplied count accepted by a search highlighting option, and the…Aug 13, 2026
CVE-2026-72639MEDIUM6.50.29%9.4Elasticsearch does not enforce an upper bound on a user-supplied count accepted by a search highlighting option, and the…Aug 13, 2026
CVE-2026-72639MEDIUM6.50.29%9.3Elasticsearch does not enforce an upper bound on a user-supplied count accepted by a search highlighting option, and the…Aug 13, 2026
CVE-2026-72638MEDIUM6.50.29%9.3Uncontrolled Recursion (CWE-674) in Elasticsearch can lead to denial of service via Input Data Manipulation (CAPEC-153).…Aug 13, 2026
CVE-2026-72638MEDIUM6.50.29%9.2Uncontrolled Recursion (CWE-674) in Elasticsearch can lead to denial of service via Input Data Manipulation (CAPEC-153).…Aug 13, 2026
CVE-2026-72638MEDIUM6.50.29%9.1Uncontrolled Recursion (CWE-674) in Elasticsearch can lead to denial of service via Input Data Manipulation (CAPEC-153).…Aug 13, 2026
CVE-2026-72638MEDIUM6.50.29%9.4Uncontrolled Recursion (CWE-674) in Elasticsearch can lead to denial of service via Input Data Manipulation (CAPEC-153).…Aug 13, 2026
CVE-2026-72638MEDIUM6.50.29%9.0Uncontrolled Recursion (CWE-674) in Elasticsearch can lead to denial of service via Input Data Manipulation (CAPEC-153).…Aug 13, 2026
CVE-2026-72636MEDIUM6.50.30%9.0Uncontrolled Recursion (CWE-674) in the Elasticsearch wildcard matching helper can lead to a denial of service via Exces…Aug 13, 2026
CVE-2026-72636MEDIUM6.50.30%9.4Uncontrolled Recursion (CWE-674) in the Elasticsearch wildcard matching helper can lead to a denial of service via Exces…Aug 13, 2026
CVE-2026-72636MEDIUM6.50.30%9.2Uncontrolled Recursion (CWE-674) in the Elasticsearch wildcard matching helper can lead to a denial of service via Exces…Aug 13, 2026
CVE-2026-72636MEDIUM6.50.30%9.1Uncontrolled Recursion (CWE-674) in the Elasticsearch wildcard matching helper can lead to a denial of service via Exces…Aug 13, 2026
CVE-2026-72636MEDIUM6.50.30%9.3Uncontrolled Recursion (CWE-674) in the Elasticsearch wildcard matching helper can lead to a denial of service via Exces…Aug 13, 2026
CVE-2026-63263MEDIUM6.50.23%9.1Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead to denial of service via Exponential Data Expansio…Jul 22, 2026
CVE-2026-63263MEDIUM6.50.23%9.0Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead to denial of service via Exponential Data Expansio…Jul 22, 2026
CVE-2026-63263MEDIUM6.50.23%9.4Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead to denial of service via Exponential Data Expansio…Jul 22, 2026
CVE-2026-63263MEDIUM6.50.23%9.3Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead to denial of service via Exponential Data Expansio…Jul 22, 2026
CVE-2026-63263MEDIUM6.50.23%9.2Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead to denial of service via Exponential Data Expansio…Jul 22, 2026
CVE-2026-63144MEDIUM6.50.23%9.3Uncontrolled Recursion (CWE-674) in Elasticsearch can lead to denial of service via a specially crafted search request s…Jul 21, 2026
CVE-2026-63144MEDIUM6.50.23%9.4Uncontrolled Recursion (CWE-674) in Elasticsearch can lead to denial of service via a specially crafted search request s…Jul 21, 2026
CVE-2026-63140MEDIUM6.50.23%9.3Reachable Assertion (CWE-617) in Elasticsearch can lead to denial of service via Input Data Manipulation (CAPEC-153). A …Jul 21, 2026
CVE-2026-63140MEDIUM6.50.23%9.0Reachable Assertion (CWE-617) in Elasticsearch can lead to denial of service via Input Data Manipulation (CAPEC-153). A …Jul 21, 2026
CVE-2026-63140MEDIUM6.50.23%9.2Reachable Assertion (CWE-617) in Elasticsearch can lead to denial of service via Input Data Manipulation (CAPEC-153). A …Jul 21, 2026
CVE-2026-63140MEDIUM6.50.23%9.1Reachable Assertion (CWE-617) in Elasticsearch can lead to denial of service via Input Data Manipulation (CAPEC-153). A …Jul 21, 2026
CVE-2026-63140MEDIUM6.50.23%9.4Reachable Assertion (CWE-617) in Elasticsearch can lead to denial of service via Input Data Manipulation (CAPEC-153). A …Jul 21, 2026
CVE-2026-63136MEDIUM6.50.23%9.1Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead to denial of service via Excessive Allocation (CAP…Jul 21, 2026
CVE-2026-63136MEDIUM6.50.23%9.0Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead to denial of service via Excessive Allocation (CAP…Jul 21, 2026
CVE-2026-63136MEDIUM6.50.23%9.3Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead to denial of service via Excessive Allocation (CAP…Jul 21, 2026
CVE-2026-63136MEDIUM6.50.23%9.2Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead to denial of service via Excessive Allocation (CAP…Jul 21, 2026
CVE-2026-56145MEDIUM6.50.29%9.4Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead to denial of service via Excessive Allocation (CAP…Jul 21, 2026
CVE-2026-56145MEDIUM6.50.29%9.1Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead to denial of service via Excessive Allocation (CAP…Jul 21, 2026
CVE-2026-56145MEDIUM6.50.29%9.3Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead to denial of service via Excessive Allocation (CAP…Jul 21, 2026
CVE-2026-56145MEDIUM6.50.29%9.0Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead to denial of service via Excessive Allocation (CAP…Jul 21, 2026
CVE-2026-56145MEDIUM6.50.29%9.2Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead to denial of service via Excessive Allocation (CAP…Jul 21, 2026
CVE-2026-56144MEDIUM5.30.23%9.0Incorrect Authorization (CWE-863) in Elasticsearch can allow an authenticated user with limited index privileges to expl…Jul 21, 2026
CVE-2026-56144MEDIUM5.30.23%9.3Incorrect Authorization (CWE-863) in Elasticsearch can allow an authenticated user with limited index privileges to expl…Jul 21, 2026
CVE-2026-56144MEDIUM5.30.23%9.4Incorrect Authorization (CWE-863) in Elasticsearch can allow an authenticated user with limited index privileges to expl…Jul 21, 2026
CVE-2026-56144MEDIUM5.30.23%9.1Incorrect Authorization (CWE-863) in Elasticsearch can allow an authenticated user with limited index privileges to expl…Jul 21, 2026
CVE-2026-56144MEDIUM5.30.23%9.2Incorrect Authorization (CWE-863) in Elasticsearch can allow an authenticated user with limited index privileges to expl…Jul 21, 2026
CVE-2026-56149MEDIUM4.90.50%9.2Allocation of Resources Without Limits or Throttling (CWE-770) in Elasticsearch can lead to a denial of service via Exce…Jul 1, 2026
CVE-2026-56149MEDIUM4.90.50%9.4Allocation of Resources Without Limits or Throttling (CWE-770) in Elasticsearch can lead to a denial of service via Exce…Jul 1, 2026
CVE-2026-56149MEDIUM4.90.50%9.3Allocation of Resources Without Limits or Throttling (CWE-770) in Elasticsearch can lead to a denial of service via Exce…Jul 1, 2026
CVE-2026-56149MEDIUM4.90.50%9.1Allocation of Resources Without Limits or Throttling (CWE-770) in Elasticsearch can lead to a denial of service via Exce…Jul 1, 2026
CVE-2026-56149MEDIUM4.90.50%9.0Allocation of Resources Without Limits or Throttling (CWE-770) in Elasticsearch can lead to a denial of service via Exce…Jul 1, 2026
CVE-2026-56148MEDIUM6.50.47%9.0Uncontrolled Recursion (CWE-674) in Elasticsearch can lead to a denial of service via Excessive Allocation (CAPEC-130). …Jul 1, 2026
CVE-2026-56148MEDIUM6.50.47%9.4Uncontrolled Recursion (CWE-674) in Elasticsearch can lead to a denial of service via Excessive Allocation (CAPEC-130). …Jul 1, 2026
CVE-2026-56148MEDIUM6.50.47%9.3Uncontrolled Recursion (CWE-674) in Elasticsearch can lead to a denial of service via Excessive Allocation (CAPEC-130). …Jul 1, 2026
CVE-2026-56148MEDIUM6.50.47%9.2Uncontrolled Recursion (CWE-674) in Elasticsearch can lead to a denial of service via Excessive Allocation (CAPEC-130). …Jul 1, 2026
CVE-2026-56148MEDIUM6.50.47%9.1Uncontrolled Recursion (CWE-674) in Elasticsearch can lead to a denial of service via Excessive Allocation (CAPEC-130). …Jul 1, 2026
CVE-2025-68390MEDIUM4.90.37%9.2Allocation of Resources Without Limits or Throttling (CWE-770) in Elasticsearch can allow an authenticated user with sna…Dec 18, 2025
CVE-2025-68390MEDIUM4.90.37%9.0Allocation of Resources Without Limits or Throttling (CWE-770) in Elasticsearch can allow an authenticated user with sna…Dec 18, 2025
CVE-2025-68390MEDIUM4.90.37%9.1Allocation of Resources Without Limits or Throttling (CWE-770) in Elasticsearch can allow an authenticated user with sna…Dec 18, 2025
CVE-2025-68384MEDIUM6.50.31%9.1Allocation of Resources Without Limits or Throttling (CWE-770) in Elasticsearch can allow a low-privileged authenticated…Dec 18, 2025
CVE-2025-68384MEDIUM6.50.31%9.0Allocation of Resources Without Limits or Throttling (CWE-770) in Elasticsearch can allow a low-privileged authenticated…Dec 18, 2025
CVE-2025-68384MEDIUM6.50.31%9.2Allocation of Resources Without Limits or Throttling (CWE-770) in Elasticsearch can allow a low-privileged authenticated…Dec 18, 2025
CVE-2025-37731MEDIUM6.80.19%9.1Improper Authentication in Elasticsearch PKI realm can lead to user impersonation via specially crafted client certifica…Dec 15, 2025
CVE-2025-37731MEDIUM6.80.19%9.2Improper Authentication in Elasticsearch PKI realm can lead to user impersonation via specially crafted client certifica…Dec 15, 2025
CVE-2025-37731MEDIUM6.80.19%9.0Improper Authentication in Elasticsearch PKI realm can lead to user impersonation via specially crafted client certifica…Dec 15, 2025

Frequently asked questions

Is Elasticsearch 9 end of life?

Partially. Some Elasticsearch 9.x releases have reached EOL. Check the version table above for the exact status of each sub-release.

What CVEs affect Elasticsearch 9?

There are 106 CVEs tracked for Elasticsearch 9.x. See the full list above with CVSS and EPSS scores.

What is the latest Elasticsearch 9 version?

The latest Elasticsearch 9.x patch release is 9.5.3, released on September 3, 2026. Always run the latest patch to benefit from all security fixes.

When was Elasticsearch 9 first released?

Elasticsearch 9.0 was initially released on August 4, 2026. See the full version timeline in the table above.

Is it safe to run Elasticsearch 9 in production?

Elasticsearch 9 is still supported and safe for production use. Ensure you are running the latest patch version (9.5.3) to have all security fixes applied.

Data sourced from endoflife.date · CVE data from NVD · EPSS from FIRST.org · KEV from CISA