Elasticsearch 9.4.7, 9.5.4 Security Update (ESA-2026-182)

Uncontrolled Resource Consumption in Elasticsearch Leading to denial of service

Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead denial of service via Excessive Allocation (CAPEC-130)

Affected Versions:

  • 9.x:
    • All versions from 9.2.0 up to and including 9.4.6
    • All versions from 9.5.0 up to and including 9.5.3

Affected Configurations:
All configurations

Solutions and Mitigations:

The issue is resolved in version 9.4.7, 9.5.4.

The versions above are the first releases that contain the fix where later releases also contain it. Elastic recommends upgrading to the most recent release available, and reviewing the known issues for your target version before upgrading.

For Users that Cannot Upgrade:

There are no workarounds for this vulnerability.

Elastic Cloud Serverless

Due to our continuous deployment and patching model, the vulnerability described in this security advisory was remediated in our Elastic Cloud Serverless offering before the public disclosure.

Severity: CVSSv3.1: Medium ( 6.5 ) - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CVE ID: CVE-2026-94396
Problem Type: CWE-400 - Uncontrolled Resource Consumption
Impact: CAPEC-130 - Excessive Allocation