Executive brief
Elasticsearch, a widely-used search and analytics platform, contains a defect in how it interprets HTTP requests that can be exploited under specific proxy configurations. An attacker could craft malicious requests to obtain confidential responses intended for other authenticated users, potentially exposing sensitive business data or customer information when the service operates behind a shared load balancer or proxy.
Technical details
The vulnerability is a classic HTTP request smuggling (CWE-444) defect in Elasticsearch's HTTP/1.1 request handling that causes inconsistent interpretation of request boundaries. The attack succeeds only when an intermediate proxy or load balancer reuses persistent connections across independent client sessions, allowing an attacker to inject smuggled requests that are processed in the context of another user's authenticated connection. An unauthenticated network attacker can exploit this to retrieve confidential responses meant for other users. The issue is fixed in Elasticsearch 8.19.20, 9.4.5, and 9.5.1; for self-managed deployments, disabling backend connection reuse on proxies mitigates cross-user disclosure but does not fix the underlying HTTP framing defect.
Affected products
- Elastic Elasticsearch 8.18.0–8.19.19, 9.0.0–9.4.4, 9.5.0
Timeline
- 2026-09-01: disclosed
- 2026-09-01: patched: Fixed in versions 8.19.20, 9.4.5, and 9.5.1