VYPR
Unrated severityNVD Advisory· Published Nov 12, 2025· Updated Nov 12, 2025

Kibana Origin Validation Error

CVE-2025-37734

Description

Origin Validation Error in Kibana can lead to Server-Side Request Forgery via a forged Origin HTTP header processed by the Observability AI Assistant.

Affected products

2
  • Elastic/Kibanallm-fuzzy2 versions
    (expand)+ 1 more
    • (no CPE)
    • (no CPE)range: 8.12.0

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.