# Elasticsearch 8.19.22, 9.4.7, 9.5.4 Security Update (ESA-2026-180)

**URL:** https://discuss.elastic.co/t/elasticsearch-8-19-22-9-4-7-9-5-4-security-update-esa-2026-180/390684
**Category:** Security Announcements
**Created:** [September 25, 2026, 8:34am UTC](https://discuss.elastic.co/t/elasticsearch-8-19-22-9-4-7-9-5-4-security-update-esa-2026-180/390684 "2026-09-25T08:34:19Z")
**Posts on this page:** 1
**Page:** 1

<div class="post-metadata">

### Author: ![kruskall](https://avatars.discourse-cdn.com/v4/letter/k/ac91a4/32.png) [@kruskall](https://discuss.elastic.co/u/kruskall)
#### Post date: [September 25, 2026, 8:34am UTC](https://discuss.elastic.co/t/elasticsearch-8-19-22-9-4-7-9-5-4-security-update-esa-2026-180/390684/1 "2026-09-25T08:34:19Z")

</div>

**Uncontrolled Resource Consumption in Elasticsearch Leading to denial of service**

Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead denial of service via Excessive Allocation (CAPEC-130)

**Affected Versions:**

- 8.x: All versions from 8.0.0 up to and including 8.19.21
- 9.x:
  - All versions from 9.0.0 up to and including 9.4.6
  - All versions from 9.5.0 up to and including 9.5.3

**Affected Configurations:**  
All configurations

**Solutions and Mitigations:**

The issue is resolved in version 8.19.22, 9.4.7, 9.5.4.

The versions above are the first releases that contain the fix where later releases also contain it. Elastic recommends upgrading to the most recent release available, and reviewing the [known issues](https://www.elastic.co/docs/release-notes) for your target version before upgrading.

**For Users that Cannot Upgrade:**

There are no workarounds for this vulnerability.

**Elastic Cloud Serverless**

Due to our continuous deployment and patching model, the vulnerability described in this security advisory was remediated in our Elastic Cloud Serverless offering before the public disclosure.

**Severity:** CVSSv3.1: Medium ( 6.5 ) - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H  
**CVE ID** : CVE-2026-94399  
**Problem Type:** CWE-400 - Uncontrolled Resource Consumption  
**Impact:** CAPEC-130 - Excessive Allocation
