# Elasticsearch 8.19.22, 9.4.8, and 9.5.5 Security Update (ESA-2026-189)

**URL:** <https://discuss.elastic.co/t/elasticsearch-8-19-22-9-4-8-and-9-5-5-security-update-esa-2026-189/390862>\
**Category:** Security Announcements\
**Created:** [October 6, 2026, 6:39pm UTC](https://discuss.elastic.co/t/elasticsearch-8-19-22-9-4-8-and-9-5-5-security-update-esa-2026-189/390862 "2026-10-06T18:39:39Z")\
**Posts on this page:** 1\
**Page:** 1

<div class="post-metadata">

**Author:** ![cronosda](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/cronosda/32/147882_2.png) [@cronosda](https://discuss.elastic.co/u/cronosda)\
**Post date:** [October 6, 2026, 6:39pm UTC](https://discuss.elastic.co/t/elasticsearch-8-19-22-9-4-8-and-9-5-5-security-update-esa-2026-189/390862/1 "2026-10-06T18:39:39Z")

</div>

**Inefficient Regular Expression Complexity in Elasticsearch Leading to Denial of Service**

Inefficient Regular Expression Complexity (CWE-1333) in Elasticsearch can lead to denial of service via Regular Expression Exponential Blowup (CAPEC-492). The ES|QL CHUNK function's recursive chunking strategy accepts a list of user-supplied regular expressions used as text-splitting separators, without validating their computational complexity or bounding their execution time. An authenticated user with read access to any text-based index can submit a specially crafted regular expression that triggers catastrophic backtracking, consuming excessive CPU on Elasticsearch worker threads and degrading query throughput for other tenants on the affected node. The cluster does not crash as a result of this issue.

**Affected Versions:**

> - 8.x: All versions from 8.19.0 up to and including 8.19.21
> - 9.x:

- All versions from 9.1.0 up to and including 9.3.8
- All versions from 9.4.0 up to and including 9.4.7
- All versions from 9.5.0 up to and including 9.5.4

Users on the 8.0.x–8.18.x and 9.0.x release lines are not affected. The chunking functionality that contains this vulnerability was not introduced until 8.19.0 and 9.1.0 respectively.

No fix is available for the 9.1.x, 9.2.x, or 9.3.x lines; users on these lines should upgrade to a supported release line.

**Affected Configurations:**

> - Deployments where an authenticated user is permitted to issue ES|QL queries using the CHUNK function's recursive chunking strategy with caller-supplied separators are affected. This applies regardless of whether an admin role is held; the built-in "viewer" role and any custom role with read access to a text-family index are sufficient.

**Solutions and Mitigations:**

This issue is resolved in Elasticsearch 8.19.22, 9.4.8, and 9.5.5.

Elastic recommends upgrading to the most recent release available, and reviewing the [known issues](https://www.elastic.co/docs/release-notes) for your target version before upgrading.

**For Users that Cannot Upgrade:**

> - There are no workarounds for this vulnerability.

**Indicators of Compromise (IOC)**

No specific indicators of compromise have been identified for this vulnerability.

**Elastic Cloud Serverless**

Due to our continuous deployment and patching model, the vulnerability described in this security advisory was remediated in our Elastic Cloud Serverless offering before the public disclosure.

**Severity:** CVSSv3.1: Medium ( 4.3 ) - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L  
**CVE ID:** CVE-2026-102408  
**Problem Type:** CWE-1333 - Inefficient Regular Expression Complexity  
**Impact:** CAPEC-492 - Regular Expression Exponential Blowup
