Junglewise Threat Intelligence

CVE-2026-78605: Elasticsearch HTTP request smuggling leading to information disclosure

CVE-2026-78605 · Severity: medium · CVSS 5.9 · Published 2026-09-01

Technologies: Elasticsearch. Vendors: Elastic.

Executive brief

Elasticsearch, a widely-used search and analytics platform, contains a defect in how it interprets HTTP requests that can be exploited under specific proxy configurations. An attacker could craft malicious requests to obtain confidential responses intended for other authenticated users, potentially exposing sensitive business data or customer information when the service operates behind a shared load balancer or proxy.

Technical details

The vulnerability is a classic HTTP request smuggling (CWE-444) defect in Elasticsearch's HTTP/1.1 request handling that causes inconsistent interpretation of request boundaries. The attack succeeds only when an intermediate proxy or load balancer reuses persistent connections across independent client sessions, allowing an attacker to inject smuggled requests that are processed in the context of another user's authenticated connection. An unauthenticated network attacker can exploit this to retrieve confidential responses meant for other users. The issue is fixed in Elasticsearch 8.19.20, 9.4.5, and 9.5.1; for self-managed deployments, disabling backend connection reuse on proxies mitigates cross-user disclosure but does not fix the underlying HTTP framing defect.

Affected products

  • Elastic Elasticsearch 8.18.0–8.19.19, 9.0.0–9.4.4, 9.5.0

Timeline

  • 2026-09-01: disclosed
  • 2026-09-01: patched: Fixed in versions 8.19.20, 9.4.5, and 9.5.1

References

Related threats