Inconsistent interpretation of HTTP requests in Elasticsearch - CVE-2026-78605

 

Inconsistent interpretation of HTTP requests in Elasticsearch - CVE-2026-78605

Published: September 1, 2026


Vulnerability identifier: #VU146652
CSH Severity: Medium
CVSS v4: 8.2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-78605
CWE-ID: CWE-444
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to inconsistent interpretation of HTTP requests in the HTTP/1.1 listener when handling crafted HTTP requests through an intermediate proxy or load balancer. A remote attacker can send crafted HTTP requests to disclose sensitive information.

Successful exploitation requires an intermediate proxy or load balancer that shares and reuses persistent backend connections across independent client sessions.


Affected software

Elasticsearch

How to mitigate CVE-2026-78605

Install security update from vendor's website.

Elasticsearch - addressed in versions 8.19.20, 9.4.5, 9.5.1

External References

Related Security Bulletins