Description
Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') (CWE-444) in Elasticsearch can lead to information disclosure via HTTP Request Smuggling (CAPEC-33). Under specific proxy deployment configurations, a network attacker could obtain confidential responses intended for other authenticated users.
Published: 2026-09-01
Score: 5.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Information Disclosure
Action: Assess Impact
AI Analysis

Impact

Elastic’s Elasticsearch product has a flaw where HTTP requests are interpreted inconsistently, a form of HTTP Request Smuggling (CWE‑444). This weakness can allow a network attacker, under specific proxy deployment configurations, to read confidential responses that were meant for other authenticated users. The vulnerability directly exposes sensitive information and can undermine the confidentiality of data exchanged with the Elasticsearch service.

Affected Systems

The affected product is Elastic:Elasticsearch. No specific version details are listed in the available information, so all deployments of Elasticsearch should be reviewed for this weakness.

Risk and Exploitability

The CVSS score of 5.9 indicates a moderate severity risk. Because the EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog, the current exploitation risk is unclear, but the attack vector is inferred to be a network attacker exploiting proxy configuration settings that allow HTTP request smuggling. When the described conditions are met, the attacker can obtain data from other users, making the impact significant even though the mathematical score is moderate.

Generated by OpenCVE AI on September 2, 2026 at 02:12 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Elasticsearch to the latest release that contains the fix for HTTP request smuggling.
  • Review and tighten proxy and load‑balancer configurations to disallow request smuggling patterns, such as relaxed parsing of HTTP headers.
  • Implement network segmentation or firewall rules to limit untrusted traffic that can reach the Elasticsearch cluster and monitor logs for abnormal request patterns.

Generated by OpenCVE AI on September 2, 2026 at 02:12 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 02 Sep 2026 19:00:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:elastic:elasticsearch:*:*:*:*:*:*:*:*
cpe:2.3:a:elastic:elasticsearch:9.5.0:*:*:*:*:*:*:*

Wed, 02 Sep 2026 02:00:00 +0000

Type Values Removed Values Added
First Time appeared Elastic
Elastic elasticsearch
Vendors & Products Elastic
Elastic elasticsearch

Tue, 01 Sep 2026 22:00:00 +0000

Type Values Removed Values Added
Description Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') (CWE-444) in Elasticsearch can lead to information disclosure via HTTP Request Smuggling (CAPEC-33). Under specific proxy deployment configurations, a network attacker could obtain confidential responses intended for other authenticated users.
Title Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') in Elasticsearch Leading to Information Disclosure
Weaknesses CWE-444
References
Metrics cvssV3_1

{'score': 5.9, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Subscriptions

Elastic Elasticsearch
cve-icon MITRE

Status: PUBLISHED

Assigner: elastic

Published:

Updated: 2026-09-01T19:41:50.325Z

Reserved: 2026-08-24T21:13:52.890Z

Link: CVE-2026-78605

cve-icon Vulnrichment

Updated: 2026-09-01T19:41:47.052Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-01T20:17:23.757

Modified: 2026-09-02T18:50:25.313

Link: CVE-2026-78605

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-02T02:15:12Z

Weaknesses
  • CWE-444

    Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')