ElasticsearchGHSA-m9gh-789g-q5pv
Elasticsearch PKI Realm Authentication Bypass Vulnerability Allows User Impersonation Through Crafted Client Certificates
Medium6.8CVE-2025-37731 · Published Dec 15, 2025 · updated Sep 10, 2026
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| org.elasticsearch:elasticsearch Maven | >= 7.0.0-alpha1, < 8.19.8 | 8.19.8 |
| >= 9.0.0-beta1, < 9.1.8 | 9.1.8 | |
| >= 9.2.0, < 9.2.2 | 9.2.2 |
Details and references
Improper Authentication in Elasticsearch PKI realm can lead to user impersonation via specially crafted client certificates. A malicious actor would need to have such a crafted client certificate signed by a legitimate, trusted Certificate Authority.
- CVSS 3.1
- CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-287, CWE-295
- Also known as
- BIT-elasticsearch-2025-37731, CVE-2025-37731
- nvd.nist.gov/vuln/detail/CVE-2025-37731
- github.com/elastic/elasticsearch/commit/cd97b8566bf56e628070021300784cb9cee0286f
- github.com/elastic/elasticsearch/commit/d8a408da79f214395845d99d241e832077045983
- github.com/elastic/elasticsearch/commit/e519fe4c51a3c887675eb7daea2f914738847f23
- discuss.elastic.co/t/elasticsearch-8-19-8-9-1-8-and-9-2-2-security-update-esa-2025-27/384063
- github.com/elastic/elasticsearch
More Elasticsearch advisories
All Elasticsearch| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Oct 102025 | Elasticsearch: Insertion of Sensitive Information into Log File via reindex API CVE-2025-37727Medium5.7fixed in 8.18.8, 8.19.5, 9.0.8, 9.1.5 | Medium5.7 | 8.18.8, 8.19.5, 9.0.8, 9.1.5 |
| May 12025 | Elasticsearch Uncontrolled Resource Consumption Vulnerability CVE-2024-52979Medium6.5fixed in 7.17.25, 8.16.0 | Medium6.5 | 7.17.25, 8.16.0 |
| Apr 82025 | Elasticsearch Vulnerable to Stack Overflow due to a Large Recursion CVE-2024-52981Medium4.9fixed in 7.17.24, 8.15.1 | Medium4.9 | 7.17.24, 8.15.1 |
| Apr 82025 | Elasticsearch Potential Node Crash due to Large Recursion in `innerForbidCircularReferences` Function CVE-2024-52980Medium6.5fixed in 8.15.1 | Medium6.5 | 8.15.1 |
| Jan 212025 | Elasticsearch allocation of resources without limits or throttling leads to crash CVE-2024-43709Medium6.5fixed in 7.17.21, 8.13.3 | Medium6.5 | 7.17.21, 8.13.3 |
| Dec 172024 | Elasticsearch Incorrect Authorization vulnerability CVE-2024-12539Mediumfixed in 8.16.2 | Medium | 8.16.2 |