Disclosure summary
Insertion of sensitive information in log file in Elasticsearch can lead to loss of confidentiality under specific preconditions when auditing requests to the reindex API https://www.elastic.co/docs/api/doc/elasticsearch/operation/operation-reindex
Source-specific records & product guidance
Sources retain their own attribution and scoring. Follow the original record to confirm affected versions, fixed releases, and configuration conditions.
GitHub Reviewed Security Advisories · GHSA-56r7-h6mw-rcfv
Open original source · Updated Sep 29, 2026
Elasticsearch: Insertion of Sensitive Information into Log File via reindex API
Source severity: MEDIUM / 0
| Ecosystem | Package | Affected range | First patched |
|---|---|---|---|
| maven | org.elasticsearch.plugin:reindex-client | >= 7.0.0, < 8.18.8 | 8.18.8 |
| maven | org.elasticsearch.plugin:reindex-client | >= 8.19.0, < 8.19.5 | 8.19.5 |
| maven | org.elasticsearch.plugin:reindex-client | >= 9.0.0-beta1, < 9.0.8 | 9.0.8 |
| maven | org.elasticsearch.plugin:reindex-client | >= 9.1.0, < 9.1.5 | 9.1.5 |
Original records & references
- NIST NVD record
- CVE Program record
- github.com — Reviewed advisory
PUBLISHED 2025-10-10T08:30:55-04:00
MODIFIED 2026-09-29T17:29:10-04:00
INGESTED 2026-10-06T11:43:08-04:00