{"id":"CVE-2025-37730","summary":"Logstash Improper Certificate Validation in TCP output","details":"Improper certificate validation in Logstash's TCP output could lead to a man-in-the-middle (MitM) attack in “client” mode, as hostname verification in TCP output was not being performed when the ssl_verification_mode =\u003e full was set.","aliases":["BIT-logstash-2025-37730"],"modified":"2026-08-12T03:51:13.883069056Z","published":"2025-05-06T17:29:07.189Z","database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/37xxx/CVE-2025-37730.json","cna_assigner":"elastic","cwe_ids":["CWE-295"]},"references":[{"type":"WEB","url":"https://discuss.elastic.co/t/logstash-8-17-6-8-18-1-and-9-0-1-security-update-esa-2025-08/377869"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/37xxx/CVE-2025-37730.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-37730"},{"type":"PACKAGE","url":"https://github.com/elastic/logstash"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/elastic/logstash","events":[{"introduced":"737f0617b0f41a50b735f2e59fd6dca67519c414"},{"fixed":"03939becb3a1a37debf605569aebea0dff9bb2f3"},{"introduced":"9e3be9602a620af998d9bfdbbb632e06ad082c82"},{"fixed":"4f9dfc74ddac310aefb1db8f0766cf47127de3d4"},{"introduced":"f15ae9fbb067e491795deeed285d44c784f997da"},{"fixed":"4e850d791be668438b0d19f729fa734d4bc7657b"}],"database_specific":{"extracted_events":[{"introduced":"8.0.0"},{"fixed":"8.17.6"},{"introduced":"8.18.0"},{"fixed":"8.18.1"},{"introduced":"9.0.0"},{"fixed":"9.0.1"}],"source":"AFFECTED_FIELD"}}],"versions":["v8.18.0","v9.0.0-rc1","v9.0.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-37730.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N"}]}