Back to Vulnerability Directory
MEDIUMFixed upstream

CVE-2026-78605

Elasticsearch: HTTP request smuggling can return other users' responses

Technology

Elasticsearch

CVSS Score

5.9 / 10.0

Affected Versions

8.18.0 to 8.19.19; 9.0.0 to 9.4.4; 9.5.0

Upstream Fix

8.19.20; 9.4.5; 9.5.1

Published

September 1, 2026

OSSeva Coverage

Fixed upstream

Description

Inconsistent interpretation of HTTP requests in Elasticsearch's HTTP/1.1 handling allows request smuggling. Under proxy configurations where a proxy or load balancer reuses persistent backend connections across independent client sessions, a network attacker could obtain confidential responses meant for other authenticated users. Elastic's workaround is to configure the proxy not to reuse backend connections across client sessions. CVSS is Elastic's score as the CNA.

Upstream record: NVD · CVE.org

Is your Elasticsearch deployment affected?

If you're running 8.18.0 to 8.19.19; 9.0.0 to 9.4.4; 9.5.0, you need this patch. Book a discovery call to get covered.