elasticsearch-8

Direct Vulnerabilities

Known vulnerabilities in the elasticsearch-8 package. This does not include vulnerabilities belonging to this package’s dependencies.

Fix vulnerabilities automatically

Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.

Fix for free
VulnerabilityVulnerable Version
  • L
CVE-2026-63144

*
  • L
CVE-2025-37727

*
  • M
Incorrect Authorization

<8.17.1-r0
  • L
CVE-2026-63136

*
  • L
CVE-2026-63263

*
  • L
CVE-2026-56145

*
  • L
CVE-2026-63140

*
  • M
CVE-2026-56144

*
  • L
CVE-2026-72679

*
  • L
CVE-2026-72647

*
  • L
CVE-2026-72678

*
  • L
CVE-2026-72686

*
  • L
CVE-2026-72683

*
  • L
CVE-2026-72639

*
  • L
CVE-2026-72656

<8.18.0-r0
  • L
CVE-2026-72684

*
  • L
CVE-2026-72685

*
  • L
CVE-2026-72687

*
  • L
CVE-2026-72638

*
  • L
CVE-2026-72636

*
  • L
CVE-2026-72645

*
  • L
CVE-2026-72642

*
  • L
Information Exposure Through Caching

*
  • L
Improper Encoding or Escaping of Output

*
  • L
Cross-site Scripting (XSS)

*
  • L
Resource Exhaustion

*
  • L
GHSA-mfg7-5gfp-c4w3

*
  • L
NULL Pointer Dereference

*
  • L
Resource Exhaustion

*
  • M
HTTP Request Smuggling

*
  • L
Resource Exhaustion

*
  • H
HTTP Request Smuggling

*
  • L
Improper Access Control

*
  • M
CRLF Injection

*
  • H
Resource Exhaustion

*
  • H
Loop with Unreachable Exit Condition ('Infinite Loop')

*
  • H
Allocation of Resources Without Limits or Throttling

*
  • L
Improperly Controlled Modification of Dynamically-Determined Object Attributes

*
  • L
GHSA-r7wm-3cxj-wff9

*
  • L
CVE-2026-56148

*
  • L
CVE-2026-56149

*
  • L
CVE-2025-14813

*
  • L
Server-Side Request Forgery (SSRF)

*
  • L
Improperly Controlled Modification of Dynamically-Determined Object Attributes

*
  • L
Incomplete Blacklist

*
  • L
Incomplete Blacklist

*
  • L
HTTP Request Smuggling

*
  • L
Improper Verification of Cryptographic Signature

*
  • M
Allocation of Resources Without Limits or Throttling

*
  • H
Resource Exhaustion

*
  • L
Allocation of Resources Without Limits or Throttling

*
  • L
Resource Exhaustion

*
  • C
Insufficient Verification of Data Authenticity

*
  • L
Improper Access Control

*
  • L
Use of Insufficiently Random Values

*
  • C
Insufficient Verification of Data Authenticity

*
  • L
CVE-2025-12183

*
  • L
Information Exposure

*