{"id":"CVE-2025-37727","aliases":["GHSA-56r7-h6mw-rcfv"],"title":"Elasticsearch: Insertion of Sensitive Information into Log File via reindex API","summary":"Elasticsearch: Insertion of Sensitive Information into Log File via reindex API","severity":"medium","cvss":5.7,"cwe":["CWE-532"],"vendor":"elasticsearch","product":"org.elasticsearch.plugin:reindex-client","ecosystem":"maven","affected":["org.elasticsearch.plugin:reindex-client >= 7.0.0, < 8.18.8","org.elasticsearch.plugin:reindex-client >= 8.19.0, < 8.19.5","org.elasticsearch.plugin:reindex-client >= 9.0.0-beta1, < 9.0.8","org.elasticsearch.plugin:reindex-client >= 9.1.0, < 9.1.5"],"patched":["org.elasticsearch.plugin:reindex-client 8.18.8","org.elasticsearch.plugin:reindex-client 8.19.5","org.elasticsearch.plugin:reindex-client 9.0.8","org.elasticsearch.plugin:reindex-client 9.1.5"],"published":"2025-10-10","updated":"2026-09-29","sourceUpdated":"2026-09-29T21:29:10Z","source":"GHSA","sourceUrl":"https://github.com/advisories/GHSA-56r7-h6mw-rcfv","references":[{"url":"https://nvd.nist.gov/vuln/detail/CVE-2025-37727"},{"url":"https://discuss.elastic.co/t/elasticsearch-8-18-8-8-19-5-9-0-8-9-1-5-security-update-esa-2025-18/382453"},{"url":"https://github.com/elastic/elasticsearch/commit/e982eef416a5e1c2a4e94236d7d3b33b5c8d07db"},{"url":"https://www.elastic.co/guide/en/elasticsearch/reference/8.18/release-notes-8.18.8.html"},{"url":"https://github.com/elastic/elasticsearch/commit/0b876b816544ff5ed07fc9d67cc584b58241e116"},{"url":"https://github.com/advisories/GHSA-56r7-h6mw-rcfv"}],"tags":["ghsa","maven"],"epss":0.00247,"epssPercentile":0.14357,"ingestedAt":"2026-09-29T21:49:08.219Z","slug":"CVE-2025-37727","body":"## Overview\n\nInsertion of sensitive information in log file in Elasticsearch can lead to loss of confidentiality under specific preconditions when auditing requests to the  reindex API https://www.elastic.co/docs/api/doc/elasticsearch/operation/operation-reindex\n\n## Affected packages\n\n- `org.elasticsearch.plugin:reindex-client >= 7.0.0, < 8.18.8`\n- `org.elasticsearch.plugin:reindex-client >= 8.19.0, < 8.19.5`\n- `org.elasticsearch.plugin:reindex-client >= 9.0.0-beta1, < 9.0.8`\n- `org.elasticsearch.plugin:reindex-client >= 9.1.0, < 9.1.5`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `org.elasticsearch.plugin:reindex-client 8.18.8`\n- `org.elasticsearch.plugin:reindex-client 8.19.5`\n- `org.elasticsearch.plugin:reindex-client 9.0.8`\n- `org.elasticsearch.plugin:reindex-client 9.1.5`","depth":"sunlit","depthScore":31,"depthScoreParts":{"impact":31.4,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}