// OSSeva Blog
SecurityElasticsearch Vulnerabilities by Version: CVEs for Elasticsearch 7.x, 8.x and 9.x
The short answer
Elastic maintains only the two most recent minor releases of the current major version and the final minor of the previous one. Today that means 9.5, 9.4 and 8.19, whose latest releases are 9.5.4, 9.4.7 and 8.19.22. Every other minor, including 9.3, which dropped out when 9.5.0 shipped on 4 August 2026, gets no more releases. Elastic separates the end of maintenance, when fixes stop, from the end of support, when its support team stops helping: for 8.x they are 15 January 2027 and 15 July 2027, and for 7.17 they were 15 April 2025 and 15 January 2026. Elastic has published 36 Elasticsearch security advisories in 2026. 9.5, 9.4 and 8.19 have a fix for every one that names them. 9.3 has a fix for 10 of the 29 that name it, and 9.0, 8.18 and 7.17 have none.
Our end-of-life pages use the end of support as the end-of-life date, so 7.17 is listed as ending on 15 January 2026, while its last fix release, 7.17.29, came out on 24 June 2025.
Elasticsearch release lines and their CVEs
Dates are from elastic.co/support/eol and the Elasticsearch releases on GitHub. The counts are the 2026 Elasticsearch advisories on discuss.elastic.co whose affected ranges include each line, and a fix counts only if the fixed release can be downloaded from artifacts.elastic.co.
| Line | Status | Latest or last release | 2026 advisories naming it | Upstream fix on this line |
|---|---|---|---|---|
| 9.5 | Maintained | 9.5.4, 15 September 2026 | 17 | All 17, by 9.5.4 |
| 9.4 | Maintained | 9.4.7, 15 September 2026 | 30 | All 30, by 9.4.7 |
| 9.3 | Out of maintenance since 4 August 2026 | 9.3.8, 21 July 2026 | 29 | 10; the 19 from August and September have no 9.3 fix |
| 9.0 to 9.2 | Out of maintenance | 9.2.8, 8 April 2026; 9.1.10, 13 January 2026; 9.0.8, 6 October 2025 | 28 each | One each on 9.2 and 9.1, for CVE-2025-66566; none on 9.0 |
| 8.19 | Maintained until 15 January 2027; supported until 15 July 2027 | 8.19.22, 23 September 2026 | 33 | All 33, by 8.19.22 |
| 8.0 to 8.18 | Out of maintenance | 8.18.8, 6 October 2025 | 28 name 8.18 | No upstream fix on these lines |
| 7.17 | Maintenance ended 15 April 2025; support ended 15 January 2026 | 7.17.29, 24 June 2025 | 3, plus four from late 2025 | Only CVE-2026-49090, fixed back in 7.17.24 |
| 7.10 | End of life; the last release under Apache 2.0 | 7.10.2, 14 January 2021 | The 7.17 list, plus every 7.x fix from 7.11 to 7.17.29 | No upstream fix on this line |
| 6.8 | End of life | 6.8.23, 13 January 2022 | CVE-2026-72683, which names every version from 5.0.0 | No upstream fix on this line |
Most 2026 advisories start their ranges at 8.0.0, because 7.17 was out of support before they were written, so a missing 7.x entry means the line was not assessed, not that it is safe. One advisory shows the gap in the other direction: CVE-2026-63136 names 9.2.9 as its fix, but no 9.2.9 is on artifacts.elastic.co. See the Elasticsearch end of life tracker for every line.
Notable Elasticsearch CVEs by release line
CVSS is NVD's own score where NVD has scored the record, otherwise Elastic's score as the CNA, or GitHub's for the bundled LZ4 library. Two Elasticsearch CVEs are in CISA's Known Exploited Vulnerabilities catalogue, CVE-2014-3120 and CVE-2015-1427, both scripting flaws from the 1.x era, added on 25 March 2022.
| CVE | Issue | CVSS | Affected | Fixed in |
|---|---|---|---|---|
| CVE-2026-72649 | A crafted trained model artifact leads to code execution through deserialization in the machine learning component | 8.8 (Elastic) | 8.0.0 to 8.19.19; 9.0.0 to 9.4.4; 9.5.0 | 8.19.20, 9.4.5, 9.5.1 |
| CVE-2026-72642 | A crafted model makes the native inference process read and write outside its allocation | 8.8 (Elastic) | 8.19.0 to 8.19.19; 9.4.0 to 9.4.4; 9.5.0 | 8.19.20, 9.4.5, 9.5.1 |
| CVE-2025-66566 | The bundled LZ4 Java decompressor leaks earlier buffer contents through the transport layer | 8.2 (GitHub, CVSS 4.0) | 7.14.0 to 7.17.29; 8.0.0 to 8.19.9; 9.0.0 to 9.1.9; 9.2.0 to 9.2.3 | 8.19.10, 9.1.10, 9.2.4 |
| CVE-2023-31418 | An unauthenticated client sending malformed HTTP requests can make a node exit with OutOfMemory | 7.5 (NVD) | Up to 7.17.12; 8.0.0 to 8.8.2 | 7.17.13, 8.9.0 |
| CVE-2024-52979 | Crafted search templates with Mustache functions crash the node | 7.5 (NVD) | Before 7.17.25; before 8.16.0 | 7.17.25, 8.16.0 |
| CVE-2025-37731 | The PKI realm accepts crafted client certificates signed by a trusted CA, allowing user impersonation | 7.4 (NVD) | All 7.x; 8.0.0 to 8.19.7; 9.0.0 to 9.1.7; 9.2.0 to 9.2.1 | 8.19.8, 9.1.8, 9.2.2 |
| CVE-2025-68384 | A low-privileged user crashes the node with oversized user settings data | 6.5 (Elastic) | All 7.x; 8.0.0 to 8.19.8; 9.0.0 to 9.1.8; 9.2.0 to 9.2.2 | 8.19.9, 9.1.9, 9.2.3 |
| CVE-2026-72683 | A simulate pipeline request builds a self-referential structure that kills the node | 6.5 (Elastic) | 5.0.0 to 8.19.18; 9.3.0 to 9.3.7; 9.4.0 to 9.4.3 | 8.19.19, 9.3.8, 9.4.4 |
| CVE-2026-49090 | A crafted bulk request holds a node's CPU until it stops serving requests | 6.5 (Elastic) | Up to 7.17.23; 8.0.0 to before 8.15.0 | 7.17.24, 8.15.0 |
| CVE-2021-22145 | Malformed queries return error messages containing earlier buffer contents, which can include documents or credentials | 6.5 (NVD) | 7.10.0 to 7.13.3 | 7.13.4 |
| CVE-2021-22144 | A malicious Grok query recurses until the node crashes | 6.5 (NVD) | Before 7.13.3 and 6.8.17 | 7.13.3, 6.8.17 |
| CVE-2026-78605 | HTTP request smuggling returns other users' responses through a proxy that reuses backend connections | 5.9 (Elastic) | 8.18.0 to 8.19.19; 9.0.0 to 9.4.4; 9.5.0 | 8.19.20, 9.4.5, 9.5.1 |
| CVE-2025-37727 | Audit logging can write reindex request bodies, including credentials, to the log | 5.7 (Elastic) | 7.0.0 to 7.17.29; 8.0.0 to 8.18.7; 8.19.0 to 8.19.4; 9.0.0 to 9.0.7; 9.1.0 to 9.1.4 | 8.18.8, 8.19.5, 9.0.8, 9.1.5 |
Almost every 2026 advisory needs an authenticated user, and most are denial of service: a single request that recurses, allocates or loops until the node dies. The two highest-rated need the privileges to upload and deploy trained models, so they matter wherever machine learning is enabled and model privileges are spread wider than the cluster administrators. CVE-2023-31418, CVE-2026-78605 and CVE-2025-66566 are the exceptions that need no login, which is why HTTP and transport ports reachable from untrusted networks raise the stakes on every older line.
For Log4Shell, Elastic's advisory says Elasticsearch 7.8 and later running on JDK 9 or later are not susceptible to remote code execution or information leakage, because of the Java Security Manager, and 7.16.3 and 6.8.23 upgraded Log4j to 2.17.1. A 7.10.2 node is protected the same way, but it still ships an older Log4j 2 jar that scanners will flag.
What each line gets
Elasticsearch 9.4 and 9.5
Both are maintained, and 9.4.7 and 9.5.4 carry every fix above that applies to them. When 9.6 ships, 9.4 leaves maintenance the way 9.3 did. Elastic's 9.x maintenance runs to at least 15 October 2027.
Elasticsearch 9.0 to 9.3
These minors stopped getting releases as soon as two newer 9.x minors existed. 9.3.8 has the fixes published up to July 2026, but none of the August and September batches, including CVE-2026-72649 and CVE-2026-78605. 9.0, 9.1 and 9.2 are further behind. Moving to 9.4 or 9.5 is a rolling upgrade within the same major version.
Elasticsearch 8.19 and older 8.x
8.19 is the only maintained 8.x minor, and 8.19.22 has a fix for all 33 of the 2026 advisories that name 8.x. Maintenance ends on 15 January 2027 and support on 15 July 2027. A cluster on 8.18 or earlier has no fix for any 2026 advisory, so the first step is 8.19.22. See Elasticsearch 8 end of life.
Elasticsearch 7.17
7.17.29 is the last release. It has no fix for CVE-2025-37731, CVE-2025-68384, CVE-2025-68390, CVE-2025-37727, CVE-2025-66566 or CVE-2026-72683, all of which list 7.x as affected. For CVE-2025-37727, set xpack.security.audit.logfile.events.emit_request_body to false, and for CVE-2025-66566 set transport.compression_scheme to deflate. Elastic lists no workaround for the PKI realm flaw. See Elasticsearch 7.17 end of life and Elasticsearch 7.17 upgrade options.
Elasticsearch 7.10.2
7.10.2 matters because it is the last Elasticsearch release under the Apache 2.0 licence, so products that embed Elasticsearch and teams that cannot accept the later licences have stayed on it. It is missing every 7.x fix since January 2021, including the unauthenticated CVE-2023-31418, CVE-2021-22145, which can expose documents or credentials in error messages, and everything in the 7.17 list. See Elasticsearch 7.10 end of life.
What to do on each line
- 9.4 and 9.5. Stay on the latest patch release.
- 9.0 to 9.3. Move to 9.4.7 or 9.5.4.
- 8.x. Move to 8.19.22 now, and plan the 9.x upgrade before maintenance ends on 15 January 2027.
- 7.17 and 7.10.2. Plan the reindex to 8.19 or 9.x, or the move to OpenSearch, or take patched builds. Until then, keep the HTTP and transport ports off untrusted networks, limit who holds machine learning, ingest and snapshot privileges, disable xpack.ml.enabled where you do not use it, and apply the audit log and transport compression settings above.
Where OSSeva fits
OSSeva ships patched builds of Elasticsearch 7.10.2 and 7.17, and covers 8.x as well, with security fixes for Elasticsearch and its bundled libraries and updates to the bundled JDK. OSSeva backports fixes of this class to the end-of-life release lines it patches, and delivers them as signed packages and container images with SBOMs. They are available now on the Patch, Assure and Operate tiers. Assure adds a security and network exposure review and a reindex and client plan for 8.x or OpenSearch, and Operate adds 24/7 cluster health monitoring with a 15-minute P1 response and executed migrations. See Elasticsearch extended support.
Tags
Related articles
ActiveMQ Classic Vulnerabilities by Version: CVEs for 5.15 to 5.19 and 6.x
October 5, 2026SecurityRedis Vulnerabilities by Version: CVEs for Redis 6.2, 7.0, 7.2, 7.4 and 8.x
October 5, 2026SecurityErlang/OTP Vulnerabilities by Version: CVEs for OTP 24 to 29 and the RabbitMQ Releases That Pin Them
October 5, 2026Ready to get your open source under control?
Talk to an OSSeva engineer about CVE coverage, compliance, and migration support for your stack.