Back to blog

// OSSeva Blog

Security

Elasticsearch Vulnerabilities by Version: CVEs for Elasticsearch 7.x, 8.x and 9.x

Matt Reynolds9 min read

The short answer

Elastic maintains only the two most recent minor releases of the current major version and the final minor of the previous one. Today that means 9.5, 9.4 and 8.19, whose latest releases are 9.5.4, 9.4.7 and 8.19.22. Every other minor, including 9.3, which dropped out when 9.5.0 shipped on 4 August 2026, gets no more releases. Elastic separates the end of maintenance, when fixes stop, from the end of support, when its support team stops helping: for 8.x they are 15 January 2027 and 15 July 2027, and for 7.17 they were 15 April 2025 and 15 January 2026. Elastic has published 36 Elasticsearch security advisories in 2026. 9.5, 9.4 and 8.19 have a fix for every one that names them. 9.3 has a fix for 10 of the 29 that name it, and 9.0, 8.18 and 7.17 have none.

Our end-of-life pages use the end of support as the end-of-life date, so 7.17 is listed as ending on 15 January 2026, while its last fix release, 7.17.29, came out on 24 June 2025.

Elasticsearch release lines and their CVEs

Dates are from elastic.co/support/eol and the Elasticsearch releases on GitHub. The counts are the 2026 Elasticsearch advisories on discuss.elastic.co whose affected ranges include each line, and a fix counts only if the fixed release can be downloaded from artifacts.elastic.co.

LineStatusLatest or last release2026 advisories naming itUpstream fix on this line
9.5Maintained9.5.4, 15 September 202617All 17, by 9.5.4
9.4Maintained9.4.7, 15 September 202630All 30, by 9.4.7
9.3Out of maintenance since 4 August 20269.3.8, 21 July 20262910; the 19 from August and September have no 9.3 fix
9.0 to 9.2Out of maintenance9.2.8, 8 April 2026; 9.1.10, 13 January 2026; 9.0.8, 6 October 202528 eachOne each on 9.2 and 9.1, for CVE-2025-66566; none on 9.0
8.19Maintained until 15 January 2027; supported until 15 July 20278.19.22, 23 September 202633All 33, by 8.19.22
8.0 to 8.18Out of maintenance8.18.8, 6 October 202528 name 8.18No upstream fix on these lines
7.17Maintenance ended 15 April 2025; support ended 15 January 20267.17.29, 24 June 20253, plus four from late 2025Only CVE-2026-49090, fixed back in 7.17.24
7.10End of life; the last release under Apache 2.07.10.2, 14 January 2021The 7.17 list, plus every 7.x fix from 7.11 to 7.17.29No upstream fix on this line
6.8End of life6.8.23, 13 January 2022CVE-2026-72683, which names every version from 5.0.0No upstream fix on this line

Most 2026 advisories start their ranges at 8.0.0, because 7.17 was out of support before they were written, so a missing 7.x entry means the line was not assessed, not that it is safe. One advisory shows the gap in the other direction: CVE-2026-63136 names 9.2.9 as its fix, but no 9.2.9 is on artifacts.elastic.co. See the Elasticsearch end of life tracker for every line.

Notable Elasticsearch CVEs by release line

CVSS is NVD's own score where NVD has scored the record, otherwise Elastic's score as the CNA, or GitHub's for the bundled LZ4 library. Two Elasticsearch CVEs are in CISA's Known Exploited Vulnerabilities catalogue, CVE-2014-3120 and CVE-2015-1427, both scripting flaws from the 1.x era, added on 25 March 2022.

CVEIssueCVSSAffectedFixed in
CVE-2026-72649A crafted trained model artifact leads to code execution through deserialization in the machine learning component8.8 (Elastic)8.0.0 to 8.19.19; 9.0.0 to 9.4.4; 9.5.08.19.20, 9.4.5, 9.5.1
CVE-2026-72642A crafted model makes the native inference process read and write outside its allocation8.8 (Elastic)8.19.0 to 8.19.19; 9.4.0 to 9.4.4; 9.5.08.19.20, 9.4.5, 9.5.1
CVE-2025-66566The bundled LZ4 Java decompressor leaks earlier buffer contents through the transport layer8.2 (GitHub, CVSS 4.0)7.14.0 to 7.17.29; 8.0.0 to 8.19.9; 9.0.0 to 9.1.9; 9.2.0 to 9.2.38.19.10, 9.1.10, 9.2.4
CVE-2023-31418An unauthenticated client sending malformed HTTP requests can make a node exit with OutOfMemory7.5 (NVD)Up to 7.17.12; 8.0.0 to 8.8.27.17.13, 8.9.0
CVE-2024-52979Crafted search templates with Mustache functions crash the node7.5 (NVD)Before 7.17.25; before 8.16.07.17.25, 8.16.0
CVE-2025-37731The PKI realm accepts crafted client certificates signed by a trusted CA, allowing user impersonation7.4 (NVD)All 7.x; 8.0.0 to 8.19.7; 9.0.0 to 9.1.7; 9.2.0 to 9.2.18.19.8, 9.1.8, 9.2.2
CVE-2025-68384A low-privileged user crashes the node with oversized user settings data6.5 (Elastic)All 7.x; 8.0.0 to 8.19.8; 9.0.0 to 9.1.8; 9.2.0 to 9.2.28.19.9, 9.1.9, 9.2.3
CVE-2026-72683A simulate pipeline request builds a self-referential structure that kills the node6.5 (Elastic)5.0.0 to 8.19.18; 9.3.0 to 9.3.7; 9.4.0 to 9.4.38.19.19, 9.3.8, 9.4.4
CVE-2026-49090A crafted bulk request holds a node's CPU until it stops serving requests6.5 (Elastic)Up to 7.17.23; 8.0.0 to before 8.15.07.17.24, 8.15.0
CVE-2021-22145Malformed queries return error messages containing earlier buffer contents, which can include documents or credentials6.5 (NVD)7.10.0 to 7.13.37.13.4
CVE-2021-22144A malicious Grok query recurses until the node crashes6.5 (NVD)Before 7.13.3 and 6.8.177.13.3, 6.8.17
CVE-2026-78605HTTP request smuggling returns other users' responses through a proxy that reuses backend connections5.9 (Elastic)8.18.0 to 8.19.19; 9.0.0 to 9.4.4; 9.5.08.19.20, 9.4.5, 9.5.1
CVE-2025-37727Audit logging can write reindex request bodies, including credentials, to the log5.7 (Elastic)7.0.0 to 7.17.29; 8.0.0 to 8.18.7; 8.19.0 to 8.19.4; 9.0.0 to 9.0.7; 9.1.0 to 9.1.48.18.8, 8.19.5, 9.0.8, 9.1.5

Almost every 2026 advisory needs an authenticated user, and most are denial of service: a single request that recurses, allocates or loops until the node dies. The two highest-rated need the privileges to upload and deploy trained models, so they matter wherever machine learning is enabled and model privileges are spread wider than the cluster administrators. CVE-2023-31418, CVE-2026-78605 and CVE-2025-66566 are the exceptions that need no login, which is why HTTP and transport ports reachable from untrusted networks raise the stakes on every older line.

For Log4Shell, Elastic's advisory says Elasticsearch 7.8 and later running on JDK 9 or later are not susceptible to remote code execution or information leakage, because of the Java Security Manager, and 7.16.3 and 6.8.23 upgraded Log4j to 2.17.1. A 7.10.2 node is protected the same way, but it still ships an older Log4j 2 jar that scanners will flag.

What each line gets

Elasticsearch 9.4 and 9.5

Both are maintained, and 9.4.7 and 9.5.4 carry every fix above that applies to them. When 9.6 ships, 9.4 leaves maintenance the way 9.3 did. Elastic's 9.x maintenance runs to at least 15 October 2027.

Elasticsearch 9.0 to 9.3

These minors stopped getting releases as soon as two newer 9.x minors existed. 9.3.8 has the fixes published up to July 2026, but none of the August and September batches, including CVE-2026-72649 and CVE-2026-78605. 9.0, 9.1 and 9.2 are further behind. Moving to 9.4 or 9.5 is a rolling upgrade within the same major version.

Elasticsearch 8.19 and older 8.x

8.19 is the only maintained 8.x minor, and 8.19.22 has a fix for all 33 of the 2026 advisories that name 8.x. Maintenance ends on 15 January 2027 and support on 15 July 2027. A cluster on 8.18 or earlier has no fix for any 2026 advisory, so the first step is 8.19.22. See Elasticsearch 8 end of life.

Elasticsearch 7.17

7.17.29 is the last release. It has no fix for CVE-2025-37731, CVE-2025-68384, CVE-2025-68390, CVE-2025-37727, CVE-2025-66566 or CVE-2026-72683, all of which list 7.x as affected. For CVE-2025-37727, set xpack.security.audit.logfile.events.emit_request_body to false, and for CVE-2025-66566 set transport.compression_scheme to deflate. Elastic lists no workaround for the PKI realm flaw. See Elasticsearch 7.17 end of life and Elasticsearch 7.17 upgrade options.

Elasticsearch 7.10.2

7.10.2 matters because it is the last Elasticsearch release under the Apache 2.0 licence, so products that embed Elasticsearch and teams that cannot accept the later licences have stayed on it. It is missing every 7.x fix since January 2021, including the unauthenticated CVE-2023-31418, CVE-2021-22145, which can expose documents or credentials in error messages, and everything in the 7.17 list. See Elasticsearch 7.10 end of life.

What to do on each line

  • 9.4 and 9.5. Stay on the latest patch release.
  • 9.0 to 9.3. Move to 9.4.7 or 9.5.4.
  • 8.x. Move to 8.19.22 now, and plan the 9.x upgrade before maintenance ends on 15 January 2027.
  • 7.17 and 7.10.2. Plan the reindex to 8.19 or 9.x, or the move to OpenSearch, or take patched builds. Until then, keep the HTTP and transport ports off untrusted networks, limit who holds machine learning, ingest and snapshot privileges, disable xpack.ml.enabled where you do not use it, and apply the audit log and transport compression settings above.

Where OSSeva fits

OSSeva ships patched builds of Elasticsearch 7.10.2 and 7.17, and covers 8.x as well, with security fixes for Elasticsearch and its bundled libraries and updates to the bundled JDK. OSSeva backports fixes of this class to the end-of-life release lines it patches, and delivers them as signed packages and container images with SBOMs. They are available now on the Patch, Assure and Operate tiers. Assure adds a security and network exposure review and a reindex and client plan for 8.x or OpenSearch, and Operate adds 24/7 cluster health monitoring with a 15-minute P1 response and executed migrations. See Elasticsearch extended support.

Tags

ElasticsearchCVEElasticsearch 7.17Elasticsearch 8.19End of Life

Ready to get your open source under control?

Talk to an OSSeva engineer about CVE coverage, compliance, and migration support for your stack.