CVE-2025-37727Medium· 5.7▾ SunlitElasticsearch: Insertion of Sensitive Information into Log File via reindex API
▾ Sunlit zone — Low / medium · no exploitation signal
impact 31.4 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via GHSA
Last analysed / modified upstream
0.2%
Insertion of sensitive information in log file in Elasticsearch can lead to loss of confidentiality under specific preconditions when auditing requests to the reindex API https://www.elastic.co/docs/api/doc/elasticsearch/operation/operation-reindex
org.elasticsearch.plugin:reindex-client >= 7.0.0, < 8.18.8org.elasticsearch.plugin:reindex-client >= 8.19.0, < 8.19.5org.elasticsearch.plugin:reindex-client >= 9.0.0-beta1, < 9.0.8org.elasticsearch.plugin:reindex-client >= 9.1.0, < 9.1.5Upgrade to a patched release:
org.elasticsearch.plugin:reindex-client 8.18.8org.elasticsearch.plugin:reindex-client 8.19.5org.elasticsearch.plugin:reindex-client 9.0.8org.elasticsearch.plugin:reindex-client 9.1.5Connected by shared product, vendor, weakness, or advisory.
CVE-2025-37731Medium· 6.8Elasticsearch PKI Realm Authentication Bypass Vulnerability Allows User Impersonation Through Crafted Client Certificates
CVE-2024-52980Medium· 6.5Elasticsearch-grok Potential Node Crash due to Large Recursion in `innerForbidCircularReferences` Function
CVE-2019-1953Medium· 6.5A vulnerability in the web portal of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, remote attacker to view a password in clear text
CVE-2024-23686Medium· 5.3DependencyCheck for Maven 9.0.0 to 9.0.6, for CLI version 9.0.0 to 9.0.5, and for Ant versions 9.0.0 to 9.0.5, when used in debug mode, allows an attacker to recover the NVD API Key from a log file.
CVE-2023-43261High· 7.5An information disclosure in Milesight UR5X, UR32L, UR32, UR35, UR41 before v35.3.0.7 allows attackers to access sensitive router components.
CVE-2026-61798High· 8.1netty-incubator-codec-ohttp: BoringSSL HPKE private key bytes exposed through toString() and exception messages