CVE-2025-37734: Kibana Origin Validation Error
Published Nov 12, 2025
·Updated
Origin Validation Error in Kibana can lead to Server-Side Request Forgery via a forged Origin HTTP header processed by the Observability AI Assistant.
Affected Software
4 affected components
Elastic Kibana
Elastic Kibana>=8.12.0<8.19.7
Elastic Kibana>=9.1.0<9.1.7
Elastic Kibana=9.2.0
Event History
Nov 12, 2025
CVE Published
via MITRE·09:57 AM
Data Sourced
via MITRE·09:57 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·10:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-37734?
CVE-2025-37734 has been rated as a medium severity vulnerability due to its potential for exploitation via Server-Side Request Forgery.
2
How do I fix CVE-2025-37734?
To fix CVE-2025-37734, upgrade to the latest version of Elastic Kibana that addresses this vulnerability.
3
What can be exploited in CVE-2025-37734?
CVE-2025-37734 can be exploited through a forged Origin HTTP header, which may lead to Server-Side Request Forgery.
4
What version of Kibana is affected by CVE-2025-37734?
CVE-2025-37734 affects multiple versions of Elastic Kibana, including the most recent releases prior to the patch.
5
Is CVE-2025-37734 being actively exploited?
There are currently no public reports indicating active exploitation of CVE-2025-37734.