{"id":"CVE-2025-37734","summary":"Kibana Origin Validation Error","details":"Origin Validation Error in Kibana can lead to Server-Side Request Forgery via a forged Origin HTTP header processed by the Observability AI Assistant.","aliases":["BIT-elk-2025-37734","BIT-kibana-2025-37734"],"modified":"2026-08-12T14:52:38.578317Z","published":"2025-11-12T09:57:22.782Z","related":["CGA-7vcq-84fr-gjm3"],"database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/37xxx/CVE-2025-37734.json","unresolved_ranges":[{"extracted_events":[{"introduced":"8.12.0"},{"last_affected":"8.19.6"},{"introduced":"9.1.0"},{"last_affected":"9.1.6"},{"introduced":"9.2.0"},{"last_affected":"9.2.0"}],"source":"AFFECTED_FIELD"}],"cna_assigner":"elastic","cwe_ids":["CWE-346"]},"references":[{"type":"WEB","url":"https://discuss.elastic.co/t/kibana-8-19-7-9-1-7-and-9-2-1-security-update-esa-2025-24/383381"},{"type":"WEB","url":"https://github.com/kibana"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/37xxx/CVE-2025-37734.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-37734"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/elastic/elasticsearch","events":[{"introduced":"1665f706fd9354802c02146c1e6b5c0fbcddfbc9"},{"fixed":"198d86868932741b4e0d184425510217febc27d1"},{"introduced":"00e7d33bf08f1476229d9d1642e2da46cfebdd53"},{"fixed":"49e091e266fdfecd2b3a96f9d390719838fb742d"},{"introduced":"25d88452371273dd27356c98598287b669a03eae"},{"last_affected":"25d88452371273dd27356c98598287b669a03eae"}],"database_specific":{"cpe":["cpe:2.3:a:elastic:kibana:*:*:*:*:*:*:*:*","cpe:2.3:a:elastic:kibana:9.2.0:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"8.12.0"},{"fixed":"8.19.7"},{"introduced":"9.1.0"},{"fixed":"9.1.7"},{"introduced":"9.2.0"},{"last_affected":"9.2.0"}],"source":["CPE_RANGE","CPE_STRING"]}}],"versions":["9.2.0","v9.1.6","v9.2.0","v9.1.5","v9.1.4","v9.1.3","v9.1.2","v9.1.1","v9.1.0"],"database_specific":{"vanir_signatures":[{"deprecated":false,"digest":{"line_hashes":["87973156245404004901157156197252476295","317301723513968645256735115182799239909","34483913267341345077734435543786141146","96430500502949260309981307877992601785","127518069945181260477538726763075744704","219337533429638017097475052148675132976","420531683640021358963488244351018441","227583903981385669652097563859624396268","329341308206552947868896370615104826051","54380763793061404957457997079793096729","257131606868264344209252935558899424447"],"threshold":0.9},"id":"CVE-2025-37734-02111b81","signature_type":"Line","signature_version":"v1","source":"https://github.com/elastic/elasticsearch/commit/198d86868932741b4e0d184425510217febc27d1","target":{"file":"x-pack/plugin/transform/qa/single-node-tests/src/javaRestTest/java/org/elasticsearch/xpack/transform/integration/TransformPivotRestIT.java"}},{"digest":{"function_hash":"244227877865042808261390982377746257537","length":641},"id":"CVE-2025-37734-1dbb4604","signature_type":"Function","signature_version":"v1","source":"https://github.com/elastic/elasticsearch/commit/198d86868932741b4e0d184425510217febc27d1","target":{"file":"x-pack/plugin/transform/src/main/java/org/elasticsearch/xpack/transform/transforms/pivot/AggregationResultUtils.java","function":"value"},"deprecated":false},{"deprecated":false,"digest":{"line_hashes":["709843642339146015468947825752612345","52503817861039737041756639012120089787","318690857755301201023824454478332786821","129113998543793770165379391235766623996"],"threshold":0.9},"id":"CVE-2025-37734-4c1779e9","signature_type":"Line","signature_version":"v1","source":"https://github.com/elastic/elasticsearch/commit/198d86868932741b4e0d184425510217febc27d1","target":{"file":"x-pack/plugin/transform/src/main/java/org/elasticsearch/xpack/transform/transforms/pivot/AggregationResultUtils.java"}}],"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-37734.json","vanir_signatures_modified":"2026-08-12T14:52:38Z"}},{"ranges":[{"type":"GIT","repo":"https://github.com/elastic/kibana","events":[{"introduced":"e9092c0a17923f4ed984456b8a5db619b0a794b3"},{"fixed":"28cf679904329ed50de370ff1e1e71f1b57996a1"},{"introduced":"9f30374092edd41719399f7ef81cb7ae78d8a3ab"},{"fixed":"6c427d979e2b3a65eea87f31ba4b65dc579ee2f0"},{"introduced":"68626ce831ffb8e4138bb24ba8762a15a569a41c"},{"last_affected":"68626ce831ffb8e4138bb24ba8762a15a569a41c"}],"database_specific":{"cpe":["cpe:2.3:a:elastic:kibana:*:*:*:*:*:*:*:*","cpe:2.3:a:elastic:kibana:9.2.0:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"8.12.0"},{"fixed":"8.19.7"},{"introduced":"9.1.0"},{"fixed":"9.1.7"},{"introduced":"9.2.0"},{"last_affected":"9.2.0"}],"source":["CPE_RANGE","CPE_STRING"]}}],"versions":["9.2.0","v9.1.6","v9.2.0","v9.1.5","v9.1.4","v9.1.2","v9.1.3","v9.1.1","v9.1.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-37734.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N"}]}