elasticsearch-fips-9.0

Direct Vulnerabilities

Known vulnerabilities in the elasticsearch-fips-9.0 package. This does not include vulnerabilities belonging to this package’s dependencies.

Fix vulnerabilities automatically

Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.

Fix for free
VulnerabilityVulnerable Version
  • L
Cross-site Scripting (XSS)

*
  • L
Resource Exhaustion

*
  • L
CVE-2026-59949

*
  • L
GHSA-mfg7-5gfp-c4w3

*
  • M
HTTP Request Smuggling

*
  • L
Resource Exhaustion

*
  • H
Allocation of Resources Without Limits or Throttling

*
  • L
Resource Exhaustion

*
  • H
Resource Exhaustion

*
  • L
Improper Access Control

*
  • H
Loop with Unreachable Exit Condition ('Infinite Loop')

*
  • H
HTTP Request Smuggling

*
  • M
CRLF Injection

*
  • L
GHSA-r7wm-3cxj-wff9

*
  • L
Improperly Controlled Modification of Dynamically-Determined Object Attributes

*
  • L
CVE-2026-56148

*
  • L
CVE-2026-56149

*
  • L
CVE-2025-14813

*
  • L
Improperly Controlled Modification of Dynamically-Determined Object Attributes

*
  • L
Incomplete Blacklist

*
  • L
Server-Side Request Forgery (SSRF)

*
  • L
Incomplete Blacklist

*
  • L
Improper Verification of Cryptographic Signature

*
  • M
Allocation of Resources Without Limits or Throttling

*
  • L
HTTP Request Smuggling

*
  • H
Resource Exhaustion

*
  • C
Insufficient Verification of Data Authenticity

*
  • C
Insufficient Verification of Data Authenticity

*
  • L
Use of Insufficiently Random Values

*
  • L
Allocation of Resources Without Limits or Throttling

*
  • L
Improper Access Control

*
  • L
Resource Exhaustion

*
  • L
Resource Exhaustion

*
  • L
CVE-2025-12183

*
  • C
HTTP Request Smuggling

*
  • L
Information Exposure

*
  • C
Improper Input Validation

*
  • L
Resource Exhaustion

*
  • C
HTTP Request Smuggling

*
  • H
HTTP Response Splitting

*
  • L
Integer Overflow or Wraparound

*
  • H
HTTP Request Smuggling

*
  • L
CRLF Injection

*
  • L
CVE-2026-0636

*
  • H
Improper Encoding or Escaping of Output

*
  • M
Improper Validation of Certificate with Host Mismatch

*
  • L
CVE-2026-5588

*
  • L
CVE-2026-5598

*
  • M
Improper Certificate Validation

*
  • H
Allocation of Resources Without Limits or Throttling

*
  • H
Improper Encoding or Escaping of Output

*
  • L
Uncontrolled Recursion

*
  • L
CVE-2025-22227

*
  • L
CVE-2025-68390

*
  • L
CRLF Injection

*
  • H
CVE-2025-37731

*
  • L
CVE-2025-68384

*
  • L
GHSA-72hv-8253-57qq

*
  • L
CVE-2025-37727

<9.0.8-r0
  • L
HTTP Request Smuggling

*