Elasticsearch
This hub aggregates every CVE we track for Elasticsearch, a product in the databases space. Use it to gauge the current risk picture and drill into individual advisories.
86
CVEs tracked
2
Critical
14
High
2
In CISA KEV
Severity distribution
MEDIUM68HIGH14LOW2CRITICAL2
Monthly trend
0
0
1
1
0
0
2
2
0
0
0
0
1
0
3
0
0
0
0
0
0
9
14
4
2024-102026-09
Latest CVEs
The 15 most recently published vulnerabilities affecting Elasticsearch.
- CVE-2026-78607Missing Authorization in Elasticsearch Leading to Information Disclosure5.4
- CVE-2026-78605Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') in Elasticsearch Leading to Information Disclosure5.9
- CVE-2026-72649Deserialization of Untrusted Data in Elasticsearch Leading to Remote Code Execution8.8
- CVE-2026-56143Allocation of Resources Without Limits or Throttling in Elasticsearch Leading to Denial of Service4.9
- CVE-2026-72636Uncontrolled Recursion in Elasticsearch Wildcard Matching Leading to Denial of Service6.5
- CVE-2026-72642Use of Out-of-range Pointer Offset in the Elasticsearch Machine Learning Native Inference Process8.8
- CVE-2026-72639Memory Allocation with Excessive Size Value in Elasticsearch Highlighting Leading to Denial of Service6.5
- CVE-2026-72638Uncontrolled Recursion in Elasticsearch Leading to Denial of Service6.5
- CVE-2026-72647Uncontrolled Recursion in Elasticsearch Leading to Denial of Service6.5
- CVE-2026-72645Memory Allocation with Excessive Size Value in Elasticsearch Leading to Denial of Service6.5
- CVE-2026-72656Memory Allocation with Excessive Size Value in Elasticsearch Leading to Denial of Service6.5
- CVE-2026-72679Uncontrolled Recursion in Elasticsearch Leading to Denial of Service6.5
- CVE-2026-72678Memory Allocation with Excessive Size Value in Elasticsearch Leading to Denial of Service6.5
- CVE-2026-72687Memory Allocation with Excessive Size Value in Elasticsearch Leading to Denial of Service6.5
- CVE-2026-72686Uncontrolled Recursion in Elasticsearch Leading to Denial of Service6.5
Product normalization is registry-driven with AI assist and human review. How it works