# How to get details about es CVE fixes

**URL:** https://discuss.elastic.co/t/how-to-get-details-about-es-cve-fixes/389615
**Category:** Elasticsearch
**Created:** [August 14, 2026, 8:43am UTC](https://discuss.elastic.co/t/how-to-get-details-about-es-cve-fixes/389615 "2026-08-14T08:43:42Z")
**Posts on this page:** 8
**Page:** 1

<div class="post-metadata">

### Author: ![manick02](https://avatars.discourse-cdn.com/v4/letter/m/7ab992/32.png) [@manick02](https://discuss.elastic.co/u/manick02)
#### Post date: [August 14, 2026, 8:43am UTC](https://discuss.elastic.co/t/how-to-get-details-about-es-cve-fixes/389615/1 "2026-08-14T08:43:42Z")

</div>

I read somewhere in the forum that Elastic does not discuss about CVE fixes in the forum. What is the right method to reach-out to elastic? There are two things we need to document for every CVE identified in ES - 1 whether the vulnerability is false positive or impacting 2. which version in the future that can potentially fix this. I am sure this question could have been asked number of times

---

<div class="post-metadata">

### Author: ![DavidTurner](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/davidturner/32/22453_2.png) [@DavidTurner](https://discuss.elastic.co/u/DavidTurner)
#### Post date: [August 14, 2026, 9:12am UTC](https://discuss.elastic.co/t/how-to-get-details-about-es-cve-fixes/389615/2 "2026-08-14T09:12:01Z")

</div>

[Security Announcements - Discuss the Elastic Stack](https://discuss.elastic.co/c/announcements/security-announcements/31) is where security announcements are made here.

[Product Security at Elastic | Elastic](https://www.elastic.co/community/security) gives some more information about this.

---

<div class="post-metadata">

### Author: ![manick02](https://avatars.discourse-cdn.com/v4/letter/m/7ab992/32.png) [@manick02](https://discuss.elastic.co/u/manick02)
#### Post date: [August 14, 2026, 9:53am UTC](https://discuss.elastic.co/t/how-to-get-details-about-es-cve-fixes/389615/3 "2026-08-14T09:53:46Z")

</div>

Thanks david. Is the information in [here](https://www.elastic.co/product-security) accurate? Here they have mentioned a email Id to reachout [-security@elastic.co](mailto:-security@elastic.co). I tried this email regarding a CVE to get a comment on whether its false positive.They redirected me to [discuss.elastic.co](http://discuss.elastic.co) here. Thats why I am wondering what is the appropriate channel to get details about a CVE (whether its impacting or what release if it is planned)

---

<div class="post-metadata">

### Author: ![DavidTurner](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/davidturner/32/22453_2.png) [@DavidTurner](https://discuss.elastic.co/u/DavidTurner)
#### Post date: [August 14, 2026, 10:10am UTC](https://discuss.elastic.co/t/how-to-get-details-about-es-cve-fixes/389615/4 "2026-08-14T10:10:18Z")

</div>

Is the CVE in question mentioned in one of the [security announcements](https://discuss.elastic.co/c/announcements/security-announcements/31)?

---

<div class="post-metadata">

### Author: ![manick02](https://avatars.discourse-cdn.com/v4/letter/m/7ab992/32.png) [@manick02](https://discuss.elastic.co/u/manick02)
#### Post date: [August 17, 2026, 9:46am UTC](https://discuss.elastic.co/t/how-to-get-details-about-es-cve-fixes/389615/5 "2026-08-17T09:46:16Z")

</div>

Hello David, Thanks for responding. I wanted to know about this - [sonatype-2022-6438](https://github.com/FasterXML/jackson-core/issues/861). I am not sure of the equivalent CVE. It was reported to me with the above scanner with message - "azure-json 1.2.0 embeds (shades) jackson-core 2.13.5, which is vulnerable to a Denial of Service attack via unrestricted numeric deserialization." I am looking to find whether which version of es this would be likely fixed. Please feel free to remove this if it violates the policy

---

<div class="post-metadata">

### Author: ![DavidTurner](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/davidturner/32/22453_2.png) [@DavidTurner](https://discuss.elastic.co/u/DavidTurner)
#### Post date: [August 17, 2026, 10:30am UTC](https://discuss.elastic.co/t/how-to-get-details-about-es-cve-fixes/389615/6 "2026-08-17T10:30:33Z")

</div>

I can't comment on the security implications here but I think your scanner is faulty as I can find nothing to indicate that Elasticsearch actually uses that version of `jackson-core`.

---

<div class="post-metadata">

### Author: ![manick02](https://avatars.discourse-cdn.com/v4/letter/m/7ab992/32.png) [@manick02](https://discuss.elastic.co/u/manick02)
#### Post date: [August 17, 2026, 11:05am UTC](https://discuss.elastic.co/t/how-to-get-details-about-es-cve-fixes/389615/7 "2026-08-17T11:05:54Z")

</div>

I can find azure-json 1.2.0 is getting shipped. Azure-jsone seem to shade jackson-core 2.13.5

---

<div class="post-metadata">

### Author: ![DavidTurner](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/davidturner/32/22453_2.png) [@DavidTurner](https://discuss.elastic.co/u/DavidTurner)
#### Post date: [August 17, 2026, 11:27am UTC](https://discuss.elastic.co/t/how-to-get-details-about-es-cve-fixes/389615/8 "2026-08-17T11:27:41Z")

</div>

Hmm I see. I think you need to try again with [security@elastic.co](mailto:security@elastic.co).
