CVE-2026-78605
EUVD-2026-6956801.09.2026, 20:17
Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') (CWE-444) in Elasticsearch can lead to information disclosure via HTTP Request Smuggling (CAPEC-33). Under specific proxy deployment configurations, a network attacker could obtain confidential responses intended for other authenticated users.Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| elastic | elasticsearch | 8.18.0 ≤ 𝑥 ≤ 8.19.19 | CNA |
| elastic | elasticsearch | 9.0.0 ≤ 𝑥 ≤ 9.4.4 | CNA |
| elastic | elasticsearch | 9.5.0 | CNA |