elasticsearch-9.2

Direct Vulnerabilities

Known vulnerabilities in the elasticsearch-9.2 package. This does not include vulnerabilities belonging to this package’s dependencies.

Fix vulnerabilities automatically

Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.

Fix for free
VulnerabilityVulnerable Version
  • L
CVE-2026-68494

<9.2.8-r19
  • L
GHSA-642r-3gj9-2pj5

<9.2.8-r19
  • L
CVE-2026-89407

<9.2.8-r19
  • L
GHSA-7hhh-6rmp-j9qf

<9.2.8-r19
  • L
GHSA-p6pp-m3f8-5c89

<9.2.8-r19
  • L
CVE-2026-89425

<9.2.8-r19
  • L
GHSA-cxp5-3px4-pw24

<9.2.8-r18
  • L
GHSA-wv8q-qhhj-9h54

<9.2.8-r18
  • L
CVE-2026-91777

<9.2.8-r18
  • L
CVE-2026-91776

<9.2.8-r18
  • L
GHSA-q4xh-88c3-wmh7

<9.2.8-r17
  • L
GHSA-vvgp-rfg2-7rr6

<9.2.8-r17
  • L
Server-Side Request Forgery (SSRF)

<9.2.8-r17
  • L
GHSA-gx83-3vf8-gh7j

<9.2.8-r17
  • L
CVE-2026-83557

<9.2.8-r17
  • L
CVE-2026-19032

<9.2.8-r17
  • L
GHSA-wjgm-6hv5-3cvf

<9.2.8-r17
  • L
CVE-2026-68497

<9.2.8-r17
  • L
GHSA-5q95-hrpc-m3w3

<9.2.8-r16
  • L
Inefficient Regular Expression Complexity

<9.2.8-r16
  • H
CVE-2026-13506

<9.2.8-r15
  • C
CVE-2026-8763

<9.2.8-r15
  • L
CVE-2026-13505

<9.2.8-r15
  • L
GHSA-9pwp-9qqc-pr26

<9.2.8-r15
  • L
GHSA-98j2-6v39-78w8

<9.2.8-r15
  • L
GHSA-qp49-qgx5-5m26

<9.2.8-r15
  • L
CVE-2026-18401

<9.2.6-r1
  • L
GHSA-6qm2-mcq7-53qp

<9.2.6-r1
  • L
Server-Side Request Forgery (SSRF)

<9.2.8-r17
  • C
Insufficient Verification of Data Authenticity

<9.2.8-r13
  • L
GHSA-hjcp-jmpx-g3qm

<9.2.8-r13
  • L
Improper Encoding or Escaping of Output

<9.2.8-r13
  • L
Improper Verification of Cryptographic Signature

<9.2.8-r13
  • L
GHSA-5gvw-p9qm-jgwh

<9.2.8-r17
  • L
GHSA-mhm7-754m-9p8w

<9.2.8-r17
  • L
GHSA-j3rv-43j4-c7qm

<9.2.8-r17
  • L
Incorrect Authorization

<9.2.8-r17
  • L
GHSA-rmj7-2vxq-3g9f

<9.2.8-r17
  • L
GHSA-xmv7-r254-6q78

<9.2.8-r13
  • L
GHSA-hgj6-7826-r7m5

<9.2.8-r17
  • L
GHSA-xx22-p4ch-683r

<9.2.8-r13
  • L
GHSA-r7wm-3cxj-wff9

<9.2.8-r19
  • C
Insufficient Verification of Data Authenticity

<9.2.8-r13
  • L
Use of Insufficiently Random Values

<9.2.8-r13
  • L
GHSA-x4gw-5cx5-pgmh

<9.2.8-r13
  • L
Missing Release of Resource after Effective Lifetime

<9.2.8-r13
  • L
GHSA-5pvg-856g-cp85

<9.2.8-r13
  • L
NULL Pointer Dereference

<9.2.8-r13
  • L
Incomplete Blacklist

<9.2.8-r17
  • L
GHSA-qv9r-c865-cp47

<9.2.8-r13
  • L
GHSA-676x-f7gg-47vc

<9.2.8-r13
  • H
Missing Release of Resource after Effective Lifetime

<9.2.8-r13
  • L
GHSA-5jmj-h7xm-6q6v

<9.2.8-r17
  • L
GHSA-3pjw-73gf-8qr5

<9.2.8-r17
  • L
Incomplete Blacklist

<9.2.8-r17
  • L
Improper Access Control

<9.2.8-r13
  • L
GHSA-c653-97m9-rcg9

<9.2.8-r13
  • L
Allocation of Resources Without Limits or Throttling

<9.2.8-r13
  • L
GHSA-mfg7-5gfp-c4w3

<9.2.8-r13
  • L
Improperly Controlled Modification of Dynamically-Determined Object Attributes

<9.2.8-r17
  • L
GHSA-3qp7-7mw8-wx86

<9.2.8-r13
  • L
Improperly Controlled Modification of Dynamically-Determined Object Attributes

<9.2.8-r17
  • L
GHSA-6cqp-g7gg-8hr5

<9.2.8-r12
  • H
Resource Exhaustion

<9.2.8-r12
  • L
Resource Exhaustion

<9.2.8-r12
  • L
GHSA-jppx-w49h-x2qq

<9.2.8-r12
  • L
HTTP Request Smuggling

<9.2.8-r12
  • L
GHSA-mvh2-crg5-v77c

<9.2.8-r12
  • L
GHSA-8c42-7qj2-3j46

<9.2.8-r12
  • L
Resource Exhaustion

<9.2.8-r12
  • L
GHSA-6jqx-86gh-f27w

<9.2.8-r12
  • L
GHSA-4mp9-239f-g9hg

<9.2.8-r12
  • L
GHSA-q4f6-jm68-57ww

<9.2.8-r12
  • L
GHSA-hvcg-qmg6-jm4c

<9.2.8-r12
  • H
HTTP Request Smuggling

<9.2.8-r12
  • L
Improper Access Control

<9.2.8-r12
  • L
GHSA-gcjf-9mgh-3p7g

<9.2.8-r12
  • M
CRLF Injection

<9.2.8-r12
  • H
Allocation of Resources Without Limits or Throttling

<9.2.8-r12
  • H
Information Exposure Through Caching

<9.2.8-r12
  • L
GHSA-v3jc-474w-2wm6

<9.2.8-r11
  • L
CVE-2026-54428

<9.2.8-r11
  • L
CVE-2026-54399

<9.2.8-r10
  • L
GHSA-hf6x-8p5f-cgmf

<9.2.8-r10
  • L
Cross-site Scripting (XSS)

<9.2.8-r9
  • L
GHSA-pmhh-3w7g-xqp8

<9.2.8-r9
  • H
Resource Exhaustion

<9.2.8-r8
  • L
GHSA-563q-j3cm-6jxm

<9.2.8-r8
  • L
GHSA-93wv-jw9v-4972

<9.2.8-r8
  • L
GHSA-c69g-56f8-xwqj

<9.2.8-r8
  • L
Resource Exhaustion

<9.2.8-r8
  • L
GHSA-c2gf-v879-257j

<9.2.8-r8
  • L
GHSA-5x3r-wrvg-rp6q

<9.2.8-r8
  • M
Allocation of Resources Without Limits or Throttling

<9.2.8-r8
  • L
Resource Exhaustion

<9.2.8-r8
  • M
HTTP Request Smuggling

<9.2.8-r8
  • H
Loop with Unreachable Exit Condition ('Infinite Loop')

<9.2.8-r7
  • L
GHSA-558v-64gr-wgg4

<9.2.8-r7
  • L
GHSA-mj4r-2hfc-f8p6

<9.2.8-r3
  • L
GHSA-xxqh-mfjm-7mv9

<9.2.8-r3
  • H
Improper Output Neutralization for Logs

<9.2.8-r3
  • L
GHSA-57rv-r2g8-2cj3

<9.2.8-r3
  • L
GHSA-3pxv-7cmr-fjr4

<9.2.8-r3
  • L
GHSA-m4cv-j2px-7723

<9.2.8-r3
  • C
HTTP Request Smuggling

<9.2.8-r3
  • C
HTTP Request Smuggling

<9.2.8-r3
  • L
Integer Overflow or Wraparound

<9.2.8-r3
  • C
Improper Input Validation

<9.2.8-r3
  • L
GHSA-445c-vh5m-36rj

<9.2.8-r3
  • L
GHSA-45q3-82m4-75jr

<9.2.8-r3
  • L
GHSA-6hg6-v5c8-fphq

<9.2.8-r3
  • L
GHSA-f6hv-jmp6-3vwv

<9.2.8-r3
  • L
GHSA-38f8-5428-x5cv

<9.2.8-r3
  • M
Improper Validation of Certificate with Host Mismatch

<9.2.8-r3
  • L
GHSA-cm33-6792-r9fm

<9.2.8-r3
  • L
GHSA-v8h7-rr48-vmmv

<9.2.8-r3
  • H
HTTP Request Smuggling

<9.2.8-r3
  • L
Resource Exhaustion

<9.2.8-r3
  • H
HTTP Response Splitting

<9.2.8-r3
  • L
Resource Exhaustion

<9.2.8-r3
  • H
Improper Encoding or Escaping of Output

<9.2.8-r3
  • L
CRLF Injection

<9.2.8-r3
  • L
GHSA-h383-gmxw-35v2

<9.2.8-r2
  • L
GHSA-p93r-85wp-75v3

<9.2.8-r2
  • L
CVE-2026-5598

<9.2.8-r2
  • H
Improper Encoding or Escaping of Output

<9.2.8-r2
  • L
GHSA-c3fc-8qff-9hwx

<9.2.8-r2
  • L
CVE-2026-0636

<9.2.8-r2
  • L
CVE-2026-5588

<9.2.8-r2
  • L
GHSA-wg6q-6289-32hp

<9.2.8-r2
  • H
Allocation of Resources Without Limits or Throttling

<9.2.8-r1
  • L
GHSA-w9fj-cfpg-grvv

<9.2.8-r1
  • L
GHSA-pwqr-wmgm-9rr8

<9.2.8-r1
  • M
Improper Certificate Validation

<9.2.8-r3
  • L
HTTP Request Smuggling

<9.2.8-r1
  • L
GHSA-vc5p-v9hr-52mj

<9.2.8-r3
  • L
GHSA-72hv-8253-57qq

<9.2.6-r1
  • L
CRLF Injection

<9.2.2-r1
  • L
GHSA-84h7-rjj3-6jx4

<9.2.2-r1