CVE-2025-25012: Elastic Kibana

Medium severity, CVSS 5.4. EPSS: 0.4% chance of exploitation in the next 30 days.

URL redirection to an untrusted site ('Open Redirect') in Kibana can lead to sending a user to an arbitrary site and server-side request forgery via a specially crafted URL.

Affected products

  • Elastic Kibana: from 7.0.0, before 7.17.29 (fixed in 7.17.29); from 8.0.0, before 8.17.8 (fixed in 8.17.8); from 8.18.0, before 8.18.3 (fixed in 8.18.3); from 9.0.0, before 9.0.3 (fixed in 9.0.3)

Published 2025-06-25. Last modified 2026-06-17.