CVE-2026-78605

Summary

Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') (CWE-444) in Elasticsearch can lead to information disclosure via HTTP Request Smuggling (CAPEC-33). Under specific proxy deployment configurations, a network attacker could obtain confidential responses intended for other authenticated users.

Affected Software

VendorProductVersion RangeStatus
ElasticElasticsearch8.18.0 <= 8.19.19affected
ElasticElasticsearch9.0.0 <= 9.4.4affected
ElasticElasticsearch9.5.0affected

Weaknesses

  • CWE-444: CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling')

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: partial

References