CVE-2026-78605
Elasticsearch: HTTP request smuggling can return other users' responses
Technology
Elasticsearch
CVSS Score
5.9 / 10.0
Affected Versions
8.18.0 to 8.19.19; 9.0.0 to 9.4.4; 9.5.0
Upstream Fix
8.19.20; 9.4.5; 9.5.1
Published
September 1, 2026
OSSeva Coverage
Fixed upstream
Description
Inconsistent interpretation of HTTP requests in Elasticsearch's HTTP/1.1 handling allows request smuggling. Under proxy configurations where a proxy or load balancer reuses persistent backend connections across independent client sessions, a network attacker could obtain confidential responses meant for other authenticated users. Elastic's workaround is to configure the proxy not to reuse backend connections across client sessions. CVSS is Elastic's score as the CNA.
Is your Elasticsearch deployment affected?
If you're running 8.18.0 to 8.19.19; 9.0.0 to 9.4.4; 9.5.0, you need this patch. Book a discovery call to get covered.