CVE-2025-37727
Elasticsearch: audit logging can record reindex request bodies containing sensitive data
Technology
Elasticsearch
CVSS Score
5.7 / 10.0
Affected Versions
7.0.0 to 7.17.29; 8.0.0 to 8.18.7; 8.19.0 to 8.19.4; 9.0.0 to 9.0.7; 9.1.0 to 9.1.4
Upstream Fix
8.18.8; 8.19.5; 9.0.8; 9.1.5
Published
October 10, 2025
OSSeva Coverage
Fixed upstream
Description
When auditing requests to the reindex API, Elasticsearch can write sensitive information to the audit log. Affected deployments have audit logging enabled, include authentication_success events, and set xpack.security.audit.logfile.events.emit_request_body to true, which is not the default. The workaround is to set emit_request_body to false. CVSS is Elastic's score as the CNA in the NVD record.
Is your Elasticsearch deployment affected?
If you're running 7.0.0 to 7.17.29; 8.0.0 to 8.18.7; 8.19.0 to 8.19.4; 9.0.0 to 9.0.7; 9.1.0 to 9.1.4, you need this patch. Book a discovery call to get covered.