Back to Vulnerability Directory
MEDIUMFixed upstream

CVE-2025-37727

Elasticsearch: audit logging can record reindex request bodies containing sensitive data

Technology

Elasticsearch

CVSS Score

5.7 / 10.0

Affected Versions

7.0.0 to 7.17.29; 8.0.0 to 8.18.7; 8.19.0 to 8.19.4; 9.0.0 to 9.0.7; 9.1.0 to 9.1.4

Upstream Fix

8.18.8; 8.19.5; 9.0.8; 9.1.5

Published

October 10, 2025

OSSeva Coverage

Fixed upstream

Description

When auditing requests to the reindex API, Elasticsearch can write sensitive information to the audit log. Affected deployments have audit logging enabled, include authentication_success events, and set xpack.security.audit.logfile.events.emit_request_body to true, which is not the default. The workaround is to set emit_request_body to false. CVSS is Elastic's score as the CNA in the NVD record.

Upstream record: NVD · CVE.org

Is your Elasticsearch deployment affected?

If you're running 7.0.0 to 7.17.29; 8.0.0 to 8.18.7; 8.19.0 to 8.19.4; 9.0.0 to 9.0.7; 9.1.0 to 9.1.4, you need this patch. Book a discovery call to get covered.