CVE-2025-37734
12.11.2025, 10:15
Origin Validation Error in Kibana can lead to Server-Side Request Forgery via a forged Origin HTTP header processed by the Observability AI Assistant.Enginsight
| Vendor | Product | Version |
|---|---|---|
| elastic | kibana | 8.12.0 ≤ 𝑥 < 8.19.7 |
| elastic | kibana | 9.1.0 ≤ 𝑥 < 9.1.7 |
| elastic | kibana | 9.2.0 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration