Skip to content
ElasticsearchGHSA-56r7-h6mw-rcfv

Elasticsearch: Insertion of Sensitive Information into Log File via reindex API

Medium5.7CVE-2025-37727 · Published Oct 10, 2025 · updated Sep 10, 2026

GitHub advisory

Affected versions

PackageAffectedFixed in
org.elasticsearch:elasticsearch
Maven
>= 7.0.0, < 8.18.88.18.8
>= 8.19.0, < 8.19.58.19.5
>= 9.0.0-beta1, < 9.0.89.0.8
>= 9.1.0, < 9.1.59.1.5
Details and references

Insertion of sensitive information in log file in Elasticsearch can lead to loss of confidentiality under specific preconditions when auditing requests to the reindex API https://www.elastic.co/docs/api/doc/elasticsearch/operation/operation-reindex

CVSS 3.1
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Severity from
GitHub (reviewed advisory)
Weakness
CWE-532
Also known as
BIT-elasticsearch-2025-37727, CVE-2025-37727

More Elasticsearch advisories

All Elasticsearch
DateAdvisory
Dec 152025Elasticsearch PKI Realm Authentication Bypass Vulnerability Allows User Impersonation Through Crafted Client Certificates
CVE-2025-37731Medium6.8fixed in 8.19.8, 9.1.8, 9.2.2
May 12025Elasticsearch Uncontrolled Resource Consumption Vulnerability
CVE-2024-52979Medium6.5fixed in 7.17.25, 8.16.0
Apr 82025Elasticsearch Vulnerable to Stack Overflow due to a Large Recursion
CVE-2024-52981Medium4.9fixed in 7.17.24, 8.15.1
Apr 82025Elasticsearch Potential Node Crash due to Large Recursion in `innerForbidCircularReferences` Function
CVE-2024-52980Medium6.5fixed in 8.15.1
Jan 212025Elasticsearch allocation of resources without limits or throttling leads to crash
CVE-2024-43709Medium6.5fixed in 7.17.21, 8.13.3
Dec 172024Elasticsearch Incorrect Authorization vulnerability
CVE-2024-12539Mediumfixed in 8.16.2

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.