CVE-2026-78605
Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') (CWE-444) in Elasticsearch can lead to information disclosure via HTTP Request Smuggling (CAPEC-33). Under specific proxy deployment configurations, a network attacker could obtain confidential responses intended for other authenticated users.
- Published Sep 1, 2026
- CVSS 5.9 medium
- 0.3% chance of exploitation in the next 30 days (EPSS)