ElasticsearchGHSA-56r7-h6mw-rcfv
Elasticsearch: Insertion of Sensitive Information into Log File via reindex API
Medium5.7CVE-2025-37727 · Published Oct 10, 2025 · updated Sep 10, 2026
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| org.elasticsearch:elasticsearch Maven | >= 7.0.0, < 8.18.8 | 8.18.8 |
| >= 8.19.0, < 8.19.5 | 8.19.5 | |
| >= 9.0.0-beta1, < 9.0.8 | 9.0.8 | |
| >= 9.1.0, < 9.1.5 | 9.1.5 |
Details and references
Insertion of sensitive information in log file in Elasticsearch can lead to loss of confidentiality under specific preconditions when auditing requests to the reindex API https://www.elastic.co/docs/api/doc/elasticsearch/operation/operation-reindex
- CVSS 3.1
- CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-532
- Also known as
- BIT-elasticsearch-2025-37727, CVE-2025-37727
- nvd.nist.gov/vuln/detail/CVE-2025-37727
- github.com/elastic/elasticsearch/commit/e982eef416a5e1c2a4e94236d7d3b33b5c8d07db
- discuss.elastic.co/t/elasticsearch-8-18-8-8-19-5-9-0-8-9-1-5-security-update-esa-2025-18/382453
- github.com/elastic/elasticsearch
- www.elastic.co/guide/en/elasticsearch/reference/8.18/release-notes-8.18.8.html
More Elasticsearch advisories
All Elasticsearch| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Dec 152025 | Elasticsearch PKI Realm Authentication Bypass Vulnerability Allows User Impersonation Through Crafted Client Certificates CVE-2025-37731Medium6.8fixed in 8.19.8, 9.1.8, 9.2.2 | Medium6.8 | 8.19.8, 9.1.8, 9.2.2 |
| May 12025 | Elasticsearch Uncontrolled Resource Consumption Vulnerability CVE-2024-52979Medium6.5fixed in 7.17.25, 8.16.0 | Medium6.5 | 7.17.25, 8.16.0 |
| Apr 82025 | Elasticsearch Vulnerable to Stack Overflow due to a Large Recursion CVE-2024-52981Medium4.9fixed in 7.17.24, 8.15.1 | Medium4.9 | 7.17.24, 8.15.1 |
| Apr 82025 | Elasticsearch Potential Node Crash due to Large Recursion in `innerForbidCircularReferences` Function CVE-2024-52980Medium6.5fixed in 8.15.1 | Medium6.5 | 8.15.1 |
| Jan 212025 | Elasticsearch allocation of resources without limits or throttling leads to crash CVE-2024-43709Medium6.5fixed in 7.17.21, 8.13.3 | Medium6.5 | 7.17.21, 8.13.3 |
| Dec 172024 | Elasticsearch Incorrect Authorization vulnerability CVE-2024-12539Mediumfixed in 8.16.2 | Medium | 8.16.2 |