---
id: CVE-2025-37727
aliases:
  - GHSA-56r7-h6mw-rcfv
title: >-
  Elasticsearch: Insertion of Sensitive Information into Log File via reindex
  API
summary: >-
  Elasticsearch: Insertion of Sensitive Information into Log File via reindex
  API
severity: medium
cvss: 5.7
cwe:
  - CWE-532
vendor: elasticsearch
product: 'org.elasticsearch.plugin:reindex-client'
ecosystem: maven
affected:
  - 'org.elasticsearch.plugin:reindex-client >= 7.0.0, < 8.18.8'
  - 'org.elasticsearch.plugin:reindex-client >= 8.19.0, < 8.19.5'
  - 'org.elasticsearch.plugin:reindex-client >= 9.0.0-beta1, < 9.0.8'
  - 'org.elasticsearch.plugin:reindex-client >= 9.1.0, < 9.1.5'
patched:
  - 'org.elasticsearch.plugin:reindex-client 8.18.8'
  - 'org.elasticsearch.plugin:reindex-client 8.19.5'
  - 'org.elasticsearch.plugin:reindex-client 9.0.8'
  - 'org.elasticsearch.plugin:reindex-client 9.1.5'
published: '2025-10-10'
updated: '2026-09-29'
sourceUpdated: '2026-09-29T21:29:10Z'
source: GHSA
sourceUrl: 'https://github.com/advisories/GHSA-56r7-h6mw-rcfv'
references:
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2025-37727'
  - url: >-
      https://discuss.elastic.co/t/elasticsearch-8-18-8-8-19-5-9-0-8-9-1-5-security-update-esa-2025-18/382453
  - url: >-
      https://github.com/elastic/elasticsearch/commit/e982eef416a5e1c2a4e94236d7d3b33b5c8d07db
  - url: >-
      https://www.elastic.co/guide/en/elasticsearch/reference/8.18/release-notes-8.18.8.html
  - url: >-
      https://github.com/elastic/elasticsearch/commit/0b876b816544ff5ed07fc9d67cc584b58241e116
  - url: 'https://github.com/advisories/GHSA-56r7-h6mw-rcfv'
tags:
  - ghsa
  - maven
epss: 0.00247
epssPercentile: 0.14357
ingestedAt: '2026-09-29T21:49:08.219Z'
---

## Overview

Insertion of sensitive information in log file in Elasticsearch can lead to loss of confidentiality under specific preconditions when auditing requests to the  reindex API https://www.elastic.co/docs/api/doc/elasticsearch/operation/operation-reindex

## Affected packages

- `org.elasticsearch.plugin:reindex-client >= 7.0.0, < 8.18.8`
- `org.elasticsearch.plugin:reindex-client >= 8.19.0, < 8.19.5`
- `org.elasticsearch.plugin:reindex-client >= 9.0.0-beta1, < 9.0.8`
- `org.elasticsearch.plugin:reindex-client >= 9.1.0, < 9.1.5`

## Remediation

Upgrade to a patched release:

- `org.elasticsearch.plugin:reindex-client 8.18.8`
- `org.elasticsearch.plugin:reindex-client 8.19.5`
- `org.elasticsearch.plugin:reindex-client 9.0.8`
- `org.elasticsearch.plugin:reindex-client 9.1.5`
