elastic / elasticsearch
24 known vulnerabilities in elastic elasticsearch.
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2026-72649 | Medium | 0.6% | 8.8 | Deserialization of Untrusted Data (CWE-502) in the Elasticsearch machine learnin… | |
| CVE-2026-72642 | Medium | 0.3% | 8.8 | The native inference process that Elasticsearch uses to evaluate uploaded machin… | |
| CVE-2026-72683 | Low | 0.4% | 6.5 | A flaw in Elasticsearch allows an authenticated user with the privileges require… | |
| CVE-2026-72686 | Low | 0.4% | 6.5 | A flaw in Elasticsearch allows a low-privileged authenticated user to submit a s… | |
| CVE-2026-56145 | Low | 0.3% | 6.5 | Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead to denial … | |
| CVE-2026-72678 | Low | 0.3% | 6.5 | Elasticsearch does not validate a size value taken from a user-supplied input be… | |
| CVE-2026-72679 | Low | 0.3% | 6.5 | Elasticsearch does not apply its configurable input length restriction to a user… | |
| CVE-2026-56143 | Low | 0.3% | 4.9 | Allocation of Resources Without Limits or Throttling (CWE-770) in Elasticsearch … | |
| CVE-2026-72636 | Low | 0.3% | 6.5 | Uncontrolled Recursion (CWE-674) in the Elasticsearch wildcard matching helper c… | |
| CVE-2026-72638 | Low | 0.3% | 6.5 | Uncontrolled Recursion (CWE-674) in Elasticsearch can lead to denial of service … | |
| CVE-2026-72639 | Low | 0.3% | 6.5 | Elasticsearch does not enforce an upper bound on a user-supplied count accepted … | |
| CVE-2026-72645 | Low | 0.3% | 6.5 | Memory Allocation with Excessive Size Value (CWE-789) in Elasticsearch can lead … | |
| CVE-2026-72647 | Low | 0.3% | 6.5 | Uncontrolled Recursion (CWE-674) in Elasticsearch can lead to denial of service … | |
| CVE-2026-72656 | Low | 0.3% | 6.5 | Memory Allocation with Excessive Size Value (CWE-789) in the ES|QL query process… | |
| CVE-2026-72684 | Low | 0.3% | 6.5 | A flaw in Elasticsearch allows an authenticated user holding only read privilege… | |
| CVE-2026-72687 | Low | 0.3% | 6.5 | A flaw in Elasticsearch allows a low-privileged authenticated user to submit a s… | |
| CVE-2026-72685 | Low | 0.3% | 4.3 | A flaw in Elasticsearch allows a low-privileged authenticated user who can index… | |
| CVE-2026-63136 | Low | 0.2% | 6.5 | Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead to denial … | |
| CVE-2026-63140 | Low | 0.2% | 6.5 | Reachable Assertion (CWE-617) in Elasticsearch can lead to denial of service via… | |
| CVE-2026-63144 | Low | 0.2% | 6.5 | Uncontrolled Recursion (CWE-674) in Elasticsearch can lead to denial of service … | |
| CVE-2026-63263 | Low | 0.2% | 6.5 | Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead to denial … | |
| CVE-2026-56144 | Low | 0.2% | 5.3 | Incorrect Authorization (CWE-863) in Elasticsearch can allow an authenticated us… | |
| CVE-2026-78605 | Low | 0.2% | 5.9 | Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') (CWE-444… | |
| CVE-2026-78607 | Low | 0.2% | 5.4 | Missing Authorization (CWE-862) in the Elasticsearch custom inference service ca… |