Inconsistent interpretation of HTTP requests in Elasticsearch - CVE-2026-78605
Published: September 1, 2026
Vulnerability details
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to inconsistent interpretation of HTTP requests in the HTTP/1.1 listener when handling crafted HTTP requests through an intermediate proxy or load balancer. A remote attacker can send crafted HTTP requests to disclose sensitive information.
Successful exploitation requires an intermediate proxy or load balancer that shares and reuses persistent backend connections across independent client sessions.