{"id":"CVE-2025-37731","details":"Improper Authentication in Elasticsearch PKI realm can lead to user impersonation via specially crafted client certificates. A malicious actor would need to have such a crafted client certificate signed by a legitimate, trusted Certificate Authority.","aliases":["BIT-elasticsearch-2025-37731","GHSA-m9gh-789g-q5pv"],"modified":"2026-02-03T07:40:33.827698Z","published":"2025-12-15T11:15:39.707Z","related":["CGA-3pr3-p5vw-w8w8"],"references":[{"type":"ADVISORY","url":"https://discuss.elastic.co/t/elasticsearch-8-19-8-9-1-8-and-9-2-2-security-update-esa-2025-27/384063"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/elastic/elasticsearch","events":[{"introduced":"112859b85d50de2a7e63f73c8fc70b99eea24291"},{"fixed":"50f58de526b746a6cc07f0cbec0e0d510f13ce52"},{"introduced":"1b6a7ece17463df5ff54a3e1302d825889aa1161"},{"fixed":"e34ace04b64e9bfa3f9e785b08e6d81f8efe314b"},{"introduced":"25d88452371273dd27356c98598287b669a03eae"},{"fixed":"ed771e6976fac1a085affabd45433234a4babeaf"}]}],"versions":["v9.2.0","v9.2.1"],"database_specific":{"vanir_signatures":[{"id":"CVE-2025-37731-02576b91","signature_version":"v1","deprecated":false,"target":{"file":"server/src/test/java/org/elasticsearch/index/mapper/ObjectMapperTests.java"},"digest":{"threshold":0.9,"line_hashes":["68138399927849634721352134518185755420","147850613433027236036605152623700717711","327000188389740633429923151686258895118","10172959214323489082800760491650379713","65443361269886129630927617686994338723","298155108180043536562430962784205298756","52873814653832550255041893621320630522","90021522265290227475556396674873281627","79384387087175924915443272008481852967","61167209927824600176085593358142878397","41039127554953808767098106284950413279","227576771387480543076492583064669675011","104769212296023054759142031798068929000","14802966055844513178032886732496567157","34552847776123648917472632940017276499","70223006317351751605419267838750819249","196738872920611836790803905397958206758","229472418704520145702034907202186369200","177045113545019378339803804601577834342","151493275089372129906488720962144138773","113955742964444453138745870489311586136","313360184205338195709154717708055635373","176588614920067748710925422156707471268","93817411643259408209912171039556945017","204146654173786478042712549839151422984","80606918017185087922293847512223548890","307393744450969728539760071468208381791","38733424725108735361733402839124835297","87907939753066740523734344138347137610","31027357382410705048304521754170394363","28365040154406185874359927426599690825","9394165925325875305888509410715358652","318740365019222253391655081978140947616","110640517104996718645610345275908244830","205237282600257966960915848375818709030","60414029022641909224535035625818073076","252891794345199494720494255207919265808","275837802033036825856201340813439212384","184997788149862749118147848863041385586","287175046254032216342511468176609154901","303872728237379203890286763270667357788","311860289605674258185627101220510443561","270857149190866052777741660052694729398","236046813325852300021807932602380215036","307420379326332044141186484644284471475","125325845340856429671203855412236669766","15045529683662557826200630401102735424","238668624604007050408677388760256219105","254338518658134227715265961127791178028","186072344647499304083466752735238677624","144514587702927865311230571639926899212","186072344647499304083466752735238677624","31847289918100433173991075090751463415","218153975580428273400475468876848802900","66329577998461793233310061445456051873","122704936996096642358845266614408805989","135623351699668921052500473425207991230","2987546166647224551580667570738946355","44033535011072801697637364726922024981","104455354587897895032374685578327125954","29305861852544863940166831125889360531","318740365019222253391655081978140947616","110640517104996718645610345275908244830","205237282600257966960915848375818709030","60414029022641909224535035625818073076","252891794345199494720494255207919265808","151830367944463461186328002465990271800","905620188681723737537789401673339603","164065995803451392906245724077704895755","222661430634779039288600648882700608088","121136338510282949925889608760540429137","265894014432718837866071129397916057680","211365802811178810304091673590762695733","121794593478820721886884947248949349365","144514587702927865311230571639926899212","186072344647499304083466752735238677624","252328721603161798292430245913012862847","19342578464054173593701942915311437038","193242444674354595796392422447815991672","285901263497971970282484643520860399695","244936532899686260041306858869372353701","144514587702927865311230571639926899212","186072344647499304083466752735238677624","31847289918100433173991075090751463415","81675142123818490137477123082239672832","35525632921218414587373379159716868659","339716797117350968817333114597030383681","247275596163285784711671108726746498326","260630312838137189620639274390437106370","113100443554544569671523854637952292105","228220178951846959947169912991250394808","54214827091822732028002061660585786544","78442152221796857000936307695246574330","296474712943126200219253473801549377867","318740365019222253391655081978140947616","110640517104996718645610345275908244830","205237282600257966960915848375818709030","60414029022641909224535035625818073076","252891794345199494720494255207919265808","302914002427477844980009829191989039398","232416928094286011541247862140696408392","26969827267657089293023203162005800048","18258043070085503558872201042773078142","144514587702927865311230571639926899212","186072344647499304083466752735238677624","31847289918100433173991075090751463415","57590549929371773998758953404113427773","297564432275064996748107792615529872914","237275216405771323140673606385620355967","214510683996162558264044833370570232413","72654982966736011287128418762695085806","333834911705079232037477283564573839579","279480536156487043893909888308495794792","310157641467686194180270059954625946583","66377445577390837788794540333257636364","219027387237095566348362662214263177000","8591354107562984127234516540591633833","110384119508583671393405503664416308956","261911929739073229446805683897821922344","107801722357230856875080553094198903781","324122429228003019111721532886039737451","95168449214107785273139393671396169707","244320101520319041738152255345777869906","44498449525173842193806950960718457778","15045529683662557826200630401102735424","238668624604007050408677388760256219105","37854035336394866392890038560573445742","243526865395971447884843779039658613150","263052536181603814636016043710081800063","134874800146001269632216134608188550094","264941124302497384550045472688360458437","313625171901517400155660258166083783910","33928150855018430748156984558469883790","80304787136648985338047548815797366486","117637331879194917778545485799333086887","317779892338661004800246546495590307620","205823188344135740775753858400400025804","91402304783045852099126643248580419595","222661430634779039288600648882700608088","121136338510282949925889608760540429137","265894014432718837866071129397916057680","211365802811178810304091673590762695733","121794593478820721886884947248949349365","144514587702927865311230571639926899212","186072344647499304083466752735238677624","167236636039173549320118860636151203630","67532916863347053783959525193412410524","120105838137587817002300549685570283303","715722007836068572821050595269748482","226626033245037423105902343243912633412","201823511306233397603077528373732143012","126988099286053569242976226100888259101","58250725195842939150061059529050840888","302788086941959941243034463229087801117","225929126535904685480408246662723034497","169880224522370942546362573474188618945","143410293312931383339539569197663019397","332675378233053532888038990540021546316","222534489967227085930269624200008550898","137536582505653505641640259819826932267","206665018788536604313254808413887925665","275997645271335853802611462918993197475","94445766877869211924508489528037950019","298705692674400723781550134951151092162","126456487534357175862056579763164446486","151600942321708675399546278069788158398","136125960658198290978882918139805027803","235368884920833833522931670398684619139","208967149232053483446439020070897195643","101220225858752023822867495826895060519","223794606743565406686956991703965072280","65442737666648459964083633828965267412","240430531540324753181317515575796745304","177502952150177949381099326652674648222","256535213181030968577638208234578368341","121374922130389305650773418326592503983","58637080887975378753014882099189297619"]},"signature_type":"Line","source":"https://github.com/elastic/elasticsearch/commit/ed771e6976fac1a085affabd45433234a4babeaf"},{"id":"CVE-2025-37731-069a95da","signature_version":"v1","deprecated":false,"target":{"function":"testSubobjectsAutoWithInnerNested","file":"server/src/test/java/org/elasticsearch/index/mapper/ObjectMapperTests.java"},"digest":{"function_hash":"230453919909553607182064331824867429681","length":597},"signature_type":"Function","source":"https://github.com/elastic/elasticsearch/commit/ed771e6976fac1a085affabd45433234a4babeaf"},{"id":"CVE-2025-37731-2e2dce6a","signature_version":"v1","deprecated":false,"target":{"file":"server/src/test/java/org/elasticsearch/index/mapper/DynamicTemplatesTests.java"},"digest":{"threshold":0.9,"line_hashes":["200644439942213327886366349375989537489","255054687698950977091803737114517646977","14773666978378916257457843342113204691","832564416395009749635820690326619371","91521280079632374852002249004770639688","216723107334051667420879693768936247500","78154210229930958062054849915100494721","190790526853598708709954230969361049158","260007555708994773394354230071835956112","286759594706935537523957827082673888245","158234413919430385486863176781681100836","278261839270627349687234491792587855263","201865259706360973153124468007720811870","206553462047885875590184092512101255631","113894769993285992650441270903927162307","60004333181036931373125292880551019246","55624703488294908073295639207932813972","53013795208308987380365966081144495977","223115611701303715235747366410834670257","318463938401891176503721670593400278528","128176123270769335454126830127620568441","282062885586493962289013815968512497577","106983106725884700773060507889881936223","162698581221570369429945715802794443562","245145142320063407334982591315199765141","14043613372097012296719486645518691083","338365348981877132050162049874354421016","157188262403873636670104360700556737553","152092510121812166619778706514007025523","335502671539371744335653506251085971525","31847289918100433173991075090751463415","164162191959750212882370204685504892894","273698534976393741958596567981203924014","278261839270627349687234491792587855263","155425970226917983666449297206175336634","122867165354055337845968892554427810229","32833268457716361190779631502216760222","293498684929861815854586026741132903692","55624703488294908073295639207932813972","53013795208308987380365966081144495977","21668164471324407053628584200473380094","101494517516448890193518247010027235833","85578681035253804942647186250330434881","16119012016438296969353433199020014576","189456659426915370279318910810724270795","192891346782859238278747268701504531361","106983106725884700773060507889881936223","162698581221570369429945715802794443562","245145142320063407334982591315199765141","15648363993768463790136771943342872804","226300612346527739828903744076922039348","218686750574291126037977490303484538326","240932655407336139825690028245594715744","236741054794789577038874997170623642001","207994037167660890263198873050374254498","235547698731638660141209879908344913209","302153171005718917566714150290926514704","227385060499280724117484825537443315605","138223200880568031331402763128411369986","301719991855254777861459596702432211373","280224097346045111445261950325424805909","152092510121812166619778706514007025523","335502671539371744335653506251085971525","31847289918100433173991075090751463415","164162191959750212882370204685504892894","273698534976393741958596567981203924014","278261839270627349687234491792587855263","189981558296772708411260072642147168955","278419833290333048258067492036728175650","98747955943160239054618742523064641451","23091836880514911353254627678147752155","253339444177136106026285402548801469320","207841380923800311516332942743561063419","325924387530191263571025187724732561269","62860168580342780865982505096486471633","256398358592216436038481520066571347695","199718862143553198958729615315051610806","39990359033854732088960964667508920522","111467830357888939315945238185634701709","80788097789648336759167936638218130820","205424891943153638025368101449404723120","270930800043537290474499137350902465184","186072344647499304083466752735238677624","120989432332537590687143960514375045820","117591820081484525988972250557871576541","237203095679833711040624937403654098028","40140771396193324552130212186155205159","329249275765129644642876248938639603231","179064598938311232668702106950190129871","33163043221457489550370394738868168254","325044766198410650752507636803866416324","38594996262285057179306556280558686769","100016182812978588889055858833685129575","243333436107077779472667348737516285100","33971435053836597931374652764555103863","92502520819335695680290897458002504465","126526395258618473776434541143539406869","260519223234277620560779342012253439649","41023667755551219451957676977259493870","273162793428204278719268820554984729216","251711225558519561957249748233574245774","148844540101237681964087651479945044795","253339444177136106026285402548801469320","207841380923800311516332942743561063419","325924387530191263571025187724732561269","62860168580342780865982505096486471633","256398358592216436038481520066571347695","199718862143553198958729615315051610806","39990359033854732088960964667508920522","111467830357888939315945238185634701709","80788097789648336759167936638218130820","205424891943153638025368101449404723120","270930800043537290474499137350902465184","186072344647499304083466752735238677624","120989432332537590687143960514375045820","117591820081484525988972250557871576541","237203095679833711040624937403654098028","49935979451580497274814364638368062586","102307823138954933481008960286815377403","285377893202500494121263446199199285022","60087541607563830869573743588582839713","111118155046148261434290347477721300490","191077757526273347663445312779021508629","30073271766849454245418385766575724055","338060806215665712502179250548920241010","53973956644136961579040061655735438646","49443594270059285212358173046801632742","29593442465631114216533220977006770405","253339444177136106026285402548801469320","207841380923800311516332942743561063419","6680963979573813996173847439248501982","238220695970889485894158689280504459009","272600921827491888826875554001751193679","310301646726573479385448538465843745768","169809164606034715058280596321114547004","212082767489569891169905539478238920692","83962757722079948410021824587840703902","26127433217900093852659088955536902774","220942464188803982055319145743892622769","287409596138391754811245436107534848956","328737797991671705624250070024019047001","9705342270023610398121469683318399696","222281097006545894106321183261213677838","139696265135757727717948078925855013317","86335295106272241662240262460328350846","252891794345199494720494255207919265808","236978476826115841306778571755356643602","116339351156447097527163854077102002490","118785499374343039666885364927866848350","244936532899686260041306858869372353701","144514587702927865311230571639926899212","186072344647499304083466752735238677624","144514587702927865311230571639926899212","186072344647499304083466752735238677624","144514587702927865311230571639926899212","186072344647499304083466752735238677624","144514587702927865311230571639926899212","186072344647499304083466752735238677624","120989432332537590687143960514375045820","117591820081484525988972250557871576541","237203095679833711040624937403654098028","27167000380254753187340222081081238237","292239704885989982464014403168172949286","272927684709759024630706896037631962585","118162034677807212300032754374714668003","54078720533976559727129755843414681296","101066710601619919104033415908949613747","56226945280023947014836944492364187640","165349856338031875878597296491011294494","262739489304460628529887561960772420773","76449923628230544197645312408880293389","308181711463584899127263029983305054019","265472800637190866074756402497387089460","261074245958581729730244193450199962723","72817601930380101221055174651628913085","107998680296349155354697433109229589500","32878464515264506958605838627730586651","187153640509627584537476964898829502135","124380566306584661669797697579644153353","253339444177136106026285402548801469320","207841380923800311516332942743561063419","262280268945252325872453476628251434467","37280395119733677749033800378664883576","303395642939888548585483471935759953311","215243956167294394329424354181241161004","19079993459453777664486025569540923256","169809164606034715058280596321114547004","224420551099283557973397632368317598124","135512335196845566072061782552027505151","245486616525064534811722236459920741665","270631750166685224426643157578989041458","302914002427477844980009829191989039398","232416928094286011541247862140696408392","26969827267657089293023203162005800048","18258043070085503558872201042773078142","144514587702927865311230571639926899212","186072344647499304083466752735238677624","144514587702927865311230571639926899212","186072344647499304083466752735238677624","144514587702927865311230571639926899212","186072344647499304083466752735238677624","144514587702927865311230571639926899212","227385060499280724117484825537443315605","27167000380254753187340222081081238237","248846915253924446762693410851661623014","284282376075212367159088628997640790042","267807729925498201306151474979488650323","277573324001487149524759055146199503225","27841960916941892208982810217738063614","114677731943720354784151847852079621752","299587440126302552644372038133277461039","242301883946953069952866705335388052383","23714095546834915230599257897567765083","320184075703730845151225843215460655828","53301465268577198340540381647090809064","106660718130536733789717345295881606117","267978295990811906273978710293445414153","258208187485446552115411254569973124277","91619025327071467849872967553407039643","216747411318788303169738672515015182154","196412731285819638307391566868832553122","336622334866390962479800991928561065585","308681609085830833250772546674054518116","65925608576443636190075198505607821202","83518754307519561119949159172211102630","108211524213171537463640932256722680049","221864865785463548221669593801850777651","117703951280089293702557822920896971923","249527602531817588737488669274846632772","269502316233296303076478786781510347066","318204297692882270546911814380536013720","82139750014852963275283665210146532708","83519842355210881258565527292184656546","308707935293347126067988499515528150616","212310977736118014198695234780430681345"]},"signature_type":"Line","source":"https://github.com/elastic/elasticsearch/commit/ed771e6976fac1a085affabd45433234a4babeaf"},{"id":"CVE-2025-37731-2f41cec7","signature_version":"v1","deprecated":false,"target":{"function":"testSubobjectsAutoRootWithInnerObject","file":"server/src/test/java/org/elasticsearch/index/mapper/ObjectMapperTests.java"},"digest":{"function_hash":"76459017763115713487165398379399966364","length":732},"signature_type":"Function","source":"https://github.com/elastic/elasticsearch/commit/ed771e6976fac1a085affabd45433234a4babeaf"},{"id":"CVE-2025-37731-304505ba","signature_version":"v1","deprecated":false,"target":{"file":"rest-api-spec/src/yamlRestTest/java/org/elasticsearch/test/rest/ClientYamlTestSuiteIT.java"},"digest":{"threshold":0.9,"line_hashes":["145754576869583785020284009191517216527","87660110113251174670685662629742926150","242477121001815790022479391143880382901","198498088486394993383498087865749938961"]},"signature_type":"Line","source":"https://github.com/elastic/elasticsearch/commit/ed771e6976fac1a085affabd45433234a4babeaf"},{"id":"CVE-2025-37731-30f50e99","signature_version":"v1","deprecated":false,"target":{"function":"scaledFloatMapping","file":"test/framework/src/main/java/org/elasticsearch/datageneration/datasource/DefaultMappingParametersHandler.java"},"digest":{"function_hash":"43213507400767033693617022101808542515","length":384},"signature_type":"Function","source":"https://github.com/elastic/elasticsearch/commit/ed771e6976fac1a085affabd45433234a4babeaf"},{"id":"CVE-2025-37731-3617d054","signature_version":"v1","deprecated":false,"target":{"file":"server/src/main/java/org/elasticsearch/index/mapper/ObjectMapper.java"},"digest":{"threshold":0.9,"line_hashes":["168399504132569159604836507301174029827","271662464049519248966055164751897640211","144285687944577422011118440267285281005","73957061525335687429047084126433646721","10095887377056469082652031199637097498","104493914508490139914717956657461013827","108154539278908321613326225445144277145","62487929156183220938707374449025998141","299405979232905749243331385385250186339","159608239217478334601744491848710296270","259122661997631514153667133355765646371","100506690225478245507375664982519489774","195209565924618483262215786803556574416","153229686942960712123979273651459778097","72482308661437532745468059982746673869","71265353951390025610017655669312230147"]},"signature_type":"Line","source":"https://github.com/elastic/elasticsearch/commit/ed771e6976fac1a085affabd45433234a4babeaf"},{"id":"CVE-2025-37731-3fa827e5","signature_version":"v1","deprecated":false,"target":{"function":"handle","file":"test/framework/src/main/java/org/elasticsearch/datageneration/datasource/DefaultMappingParametersHandler.java"},"digest":{"function_hash":"259108022443773244233283615859410225605","length":1480},"signature_type":"Function","source":"https://github.com/elastic/elasticsearch/commit/ed771e6976fac1a085affabd45433234a4babeaf"},{"id":"CVE-2025-37731-3ff89aa4","signature_version":"v1","deprecated":false,"target":{"file":"test/framework/src/main/java/org/elasticsearch/datageneration/datasource/DefaultMappingParametersHandler.java"},"digest":{"threshold":0.9,"line_hashes":["49631404406785532175177304165093529398","88572279212247506802687499716468530783","317252187161223635465736427931975833299","212298641190641363016421536288291680078","174730498190453193336225800614516721884","65571642211792644076580931293773097263","257889109213876007362097186859663423035","9705014287569124419661927378211809656","76529030211118752752240628170888556977","187541956037016884255399645689728117618","148643049494038790179027932340810751308","211417410605482347438065771455081487281","217749249914126265895283903370357782990","91196652598933014300564131014331086282","95277726760185620658773141111526634534","91177208712623951258248245391121027440","254865790269804667340731519634992908239","197136057642953852416857271187378569361","288200083210376076684344456286880442113","184704843855521973029445283112308041799","301492802452558864651187731063529370066","188682044117348655928735065410192821854","91716532819001364371444334445879304794","329728362247328100981882766955741558912","296479200130578965397317813654658517442","232564754309446851750544542955794926035","159127287647685920789967228995428499779","262950172429887117010401621638459495861","138088696561984634382464492491521893844","142115548468385870757016218978987051393","321530532996215391764230288637897842118","239451402268268619618454912208850469560","205754713985628908790605787180351948971","204398911428014350423984782360774801939","100041262356221297324914342461784241807","294011017231541457486160860207631168174","137845185882359563616904476277532645173","245478883996485651300023033163970551910","312724213094235529529617389543243749093","28291863227938687471972104392914530436"]},"signature_type":"Line","source":"https://github.com/elastic/elasticsearch/commit/ed771e6976fac1a085affabd45433234a4babeaf"},{"id":"CVE-2025-37731-403e4831","signature_version":"v1","deprecated":false,"target":{"function":"testSubobjectsAutoFlatPaths","file":"server/src/test/java/org/elasticsearch/index/mapper/DynamicTemplatesTests.java"},"digest":{"function_hash":"119216173968097310788452597632719768031","length":507},"signature_type":"Function","source":"https://github.com/elastic/elasticsearch/commit/ed771e6976fac1a085affabd45433234a4babeaf"},{"id":"CVE-2025-37731-40ade4b9","signature_version":"v1","deprecated":false,"target":{"function":"testSubobjectsAutoWithInnerNestedFromDynamicTemplate","file":"server/src/test/java/org/elasticsearch/index/mapper/DynamicTemplatesTests.java"},"digest":{"function_hash":"28243120458251470345135002158457905373","length":1201},"signature_type":"Function","source":"https://github.com/elastic/elasticsearch/commit/ed771e6976fac1a085affabd45433234a4babeaf"},{"id":"CVE-2025-37731-457d6b8a","signature_version":"v1","deprecated":false,"target":{"function":"testSubobjectsAutoRoot","file":"server/src/test/java/org/elasticsearch/index/mapper/ObjectMapperTests.java"},"digest":{"function_hash":"265767516436973573645219326888144484316","length":773},"signature_type":"Function","source":"https://github.com/elastic/elasticsearch/commit/ed771e6976fac1a085affabd45433234a4babeaf"},{"id":"CVE-2025-37731-4fe7b2cf","signature_version":"v1","deprecated":false,"target":{"function":"testSubobjectsWithRootObjectMapperNamespaceValidator","file":"server/src/test/java/org/elasticsearch/index/mapper/RootObjectMapperTests.java"},"digest":{"function_hash":"191173331897888432400736488810324981330","length":1709},"signature_type":"Function","source":"https://github.com/elastic/elasticsearch/commit/ed771e6976fac1a085affabd45433234a4babeaf"},{"id":"CVE-2025-37731-54cf91e4","signature_version":"v1","deprecated":false,"target":{"file":"qa/ccs-common-rest/src/yamlRestTest/java/org/elasticsearch/test/rest/yaml/CcsCommonYamlTestSuiteIT.java"},"digest":{"threshold":0.9,"line_hashes":["337714869526640637047388273402624802632","235939968214185121577409805877311780777","126232292057902501803043861408555256558","45552911308487327804117958502998495648"]},"signature_type":"Line","source":"https://github.com/elastic/elasticsearch/commit/ed771e6976fac1a085affabd45433234a4babeaf"},{"id":"CVE-2025-37731-55dbeb86","signature_version":"v1","deprecated":false,"target":{"file":"server/src/test/java/org/elasticsearch/index/mapper/RootObjectMapperTests.java"},"digest":{"threshold":0.9,"line_hashes":["222748493285558261272529262158116783810","338284668641738012222483721617998957089","62762496331947187158660116097216591608","165865525206479490102885981789516202249","179208173440560314112313879635408294690","152108949139239175787886052019883740321"]},"signature_type":"Line","source":"https://github.com/elastic/elasticsearch/commit/ed771e6976fac1a085affabd45433234a4babeaf"},{"id":"CVE-2025-37731-65731216","signature_version":"v1","deprecated":false,"target":{"function":"testSubobjectsAutoArrayOfObjects","file":"server/src/test/java/org/elasticsearch/index/mapper/DynamicTemplatesTests.java"},"digest":{"function_hash":"331355465644114888141567585253316122222","length":795},"signature_type":"Function","source":"https://github.com/elastic/elasticsearch/commit/ed771e6976fac1a085affabd45433234a4babeaf"},{"id":"CVE-2025-37731-6fcbdfda","signature_version":"v1","deprecated":false,"target":{"file":"x-pack/plugin/src/yamlRestTest/java/org/elasticsearch/xpack/test/rest/XPackRestIT.java"},"digest":{"threshold":0.9,"line_hashes":["167002637822650279328165705673172612845","138667402574644979978954394496510966066","236280744293293243480035421076233765915","287723152120630545685965872573276202734"]},"signature_type":"Line","source":"https://github.com/elastic/elasticsearch/commit/ed771e6976fac1a085affabd45433234a4babeaf"},{"id":"CVE-2025-37731-717bb469","signature_version":"v1","deprecated":false,"target":{"function":"keywordMapping","file":"test/framework/src/main/java/org/elasticsearch/datageneration/datasource/DefaultMappingParametersHandler.java"},"digest":{"function_hash":"100986179295598763724742577845057441062","length":623},"signature_type":"Function","source":"https://github.com/elastic/elasticsearch/commit/ed771e6976fac1a085affabd45433234a4babeaf"},{"id":"CVE-2025-37731-77f2ef0f","signature_version":"v1","deprecated":false,"target":{"file":"qa/ccs-common-rest/src/yamlRestTest/java/org/elasticsearch/test/rest/yaml/RcsCcsCommonYamlTestSuiteIT.java"},"digest":{"threshold":0.9,"line_hashes":["51346655670653558335768463822589705541","269107923654925544404244073378340300753","246779691602097864517079922297372868637","167986972193883587275720877541105627931"]},"signature_type":"Line","source":"https://github.com/elastic/elasticsearch/commit/ed771e6976fac1a085affabd45433234a4babeaf"},{"id":"CVE-2025-37731-7b24a82b","signature_version":"v1","deprecated":false,"target":{"function":"testSubobjectAutoDynamicNested","file":"server/src/test/java/org/elasticsearch/index/mapper/DynamicTemplatesTests.java"},"digest":{"function_hash":"132485860531510518688073217497916142618","length":1052},"signature_type":"Function","source":"https://github.com/elastic/elasticsearch/commit/ed771e6976fac1a085affabd45433234a4babeaf"},{"id":"CVE-2025-37731-7b38a397","signature_version":"v1","deprecated":false,"target":{"file":"libs/ssl-config/src/main/java/org/elasticsearch/common/ssl/DerParser.java"},"digest":{"threshold":0.9,"line_hashes":["51550193863884045934320633866015297104","331630246968815451063354319351946329234","186592295080528027987154635525856192062","75995982543764003382939960430245009492"]},"signature_type":"Line","source":"https://github.com/elastic/elasticsearch/commit/50f58de526b746a6cc07f0cbec0e0d510f13ce52"},{"id":"CVE-2025-37731-7e790cab","signature_version":"v1","deprecated":false,"target":{"function":"getLength","file":"libs/ssl-config/src/main/java/org/elasticsearch/common/ssl/DerParser.java"},"digest":{"function_hash":"87673803415819436679596541002810312405","length":533},"signature_type":"Function","source":"https://github.com/elastic/elasticsearch/commit/e34ace04b64e9bfa3f9e785b08e6d81f8efe314b"},{"id":"CVE-2025-37731-86ec9b53","signature_version":"v1","deprecated":false,"target":{"file":"x-pack/qa/multi-project/xpack-rest-tests-with-multiple-projects/src/yamlRestTest/java/org/elasticsearch/multiproject/test/XpackWithMultipleProjectsClientYamlTestSuiteIT.java"},"digest":{"threshold":0.9,"line_hashes":["102436066968306687174040435300375808007","266544324008049102501641859468762282197","336445804537588956100714671114681337740","297354573700478387371727695814902781139"]},"signature_type":"Line","source":"https://github.com/elastic/elasticsearch/commit/ed771e6976fac1a085affabd45433234a4babeaf"},{"id":"CVE-2025-37731-88d704cb","signature_version":"v1","deprecated":false,"target":{"function":"testSubobjectsAutoRootWithInnerNested","file":"server/src/test/java/org/elasticsearch/index/mapper/ObjectMapperTests.java"},"digest":{"function_hash":"74531160286327120451700012675083144792","length":456},"signature_type":"Function","source":"https://github.com/elastic/elasticsearch/commit/ed771e6976fac1a085affabd45433234a4babeaf"},{"id":"CVE-2025-37731-8a468a8b","signature_version":"v1","deprecated":false,"target":{"function":"commonMappingParameters","file":"test/framework/src/main/java/org/elasticsearch/datageneration/datasource/DefaultMappingParametersHandler.java"},"digest":{"function_hash":"203248767295807374005869225486245012610","length":386},"signature_type":"Function","source":"https://github.com/elastic/elasticsearch/commit/ed771e6976fac1a085affabd45433234a4babeaf"},{"id":"CVE-2025-37731-9640414b","signature_version":"v1","deprecated":false,"target":{"function":"testDynamicSubobjectsAutoDynamicFalse","file":"server/src/test/java/org/elasticsearch/index/mapper/DynamicTemplatesTests.java"},"digest":{"function_hash":"27079942729627897828406202460404250175","length":1673},"signature_type":"Function","source":"https://github.com/elastic/elasticsearch/commit/ed771e6976fac1a085affabd45433234a4babeaf"},{"id":"CVE-2025-37731-9b35c210","signature_version":"v1","deprecated":false,"target":{"file":"x-pack/qa/core-rest-tests-with-security/src/yamlRestTest/java/org/elasticsearch/xpack/security/CoreWithSecurityClientYamlTestSuiteIT.java"},"digest":{"threshold":0.9,"line_hashes":["56153378962876869368991792937436579775","94122014742229471468473721264419072088","242477121001815790022479391143880382901","198498088486394993383498087865749938961"]},"signature_type":"Line","source":"https://github.com/elastic/elasticsearch/commit/ed771e6976fac1a085affabd45433234a4babeaf"},{"id":"CVE-2025-37731-ab506695","signature_version":"v1","deprecated":false,"target":{"function":"testMergeEnabledForIndexTemplates","file":"server/src/test/java/org/elasticsearch/index/mapper/ObjectMapperTests.java"},"digest":{"function_hash":"269642977051922449286815639073122027270","length":1723},"signature_type":"Function","source":"https://github.com/elastic/elasticsearch/commit/ed771e6976fac1a085affabd45433234a4babeaf"},{"id":"CVE-2025-37731-bc43799a","signature_version":"v1","deprecated":false,"target":{"function":"testSubobjectsAutoStructuredPaths","file":"server/src/test/java/org/elasticsearch/index/mapper/DynamicTemplatesTests.java"},"digest":{"function_hash":"75899190023757879320721873255516997993","length":609},"signature_type":"Function","source":"https://github.com/elastic/elasticsearch/commit/ed771e6976fac1a085affabd45433234a4babeaf"},{"id":"CVE-2025-37731-c33cb13d","signature_version":"v1","deprecated":false,"target":{"function":"testSubobjectsAuto","file":"server/src/test/java/org/elasticsearch/index/mapper/ObjectMapperTests.java"},"digest":{"function_hash":"279510395585520247864587631093278235975","length":888},"signature_type":"Function","source":"https://github.com/elastic/elasticsearch/commit/ed771e6976fac1a085affabd45433234a4babeaf"},{"id":"CVE-2025-37731-c79c8bab","signature_version":"v1","deprecated":false,"target":{"function":"booleanMapping","file":"test/framework/src/main/java/org/elasticsearch/datageneration/datasource/DefaultMappingParametersHandler.java"},"digest":{"function_hash":"242499518014995475490700137571356995492","length":323},"signature_type":"Function","source":"https://github.com/elastic/elasticsearch/commit/ed771e6976fac1a085affabd45433234a4babeaf"},{"id":"CVE-2025-37731-cd8f4f67","signature_version":"v1","deprecated":false,"target":{"function":"testFlattenSubobjectsAuto","file":"server/src/test/java/org/elasticsearch/index/mapper/ObjectMapperTests.java"},"digest":{"function_hash":"12278784840292804595095873359323044922","length":606},"signature_type":"Function","source":"https://github.com/elastic/elasticsearch/commit/ed771e6976fac1a085affabd45433234a4babeaf"},{"id":"CVE-2025-37731-d0206628","signature_version":"v1","deprecated":false,"target":{"function":"from","file":"server/src/main/java/org/elasticsearch/index/mapper/ObjectMapper.java"},"digest":{"function_hash":"67322187011354355262454205552209472672","length":428},"signature_type":"Function","source":"https://github.com/elastic/elasticsearch/commit/ed771e6976fac1a085affabd45433234a4babeaf"},{"id":"CVE-2025-37731-db753327","signature_version":"v1","deprecated":false,"target":{"function":"testSubobjectsAutoWithInnerObject","file":"server/src/test/java/org/elasticsearch/index/mapper/ObjectMapperTests.java"},"digest":{"function_hash":"219822578401819749286496933413128675417","length":996},"signature_type":"Function","source":"https://github.com/elastic/elasticsearch/commit/ed771e6976fac1a085affabd45433234a4babeaf"},{"id":"CVE-2025-37731-eb3cf17f","signature_version":"v1","deprecated":false,"target":{"file":"qa/smoke-test-multinode/src/yamlRestTest/java/org/elasticsearch/smoketest/SmokeTestMultiNodeClientYamlTestSuiteIT.java"},"digest":{"threshold":0.9,"line_hashes":["52758470466186084662982829804271774846","186212887030800942106819774609980870077","242477121001815790022479391143880382901","198498088486394993383498087865749938961"]},"signature_type":"Line","source":"https://github.com/elastic/elasticsearch/commit/ed771e6976fac1a085affabd45433234a4babeaf"},{"id":"CVE-2025-37731-ec99c0f8","signature_version":"v1","deprecated":false,"target":{"file":"libs/ssl-config/src/main/java/org/elasticsearch/common/ssl/DerParser.java"},"digest":{"threshold":0.9,"line_hashes":["51550193863884045934320633866015297104","331630246968815451063354319351946329234","186592295080528027987154635525856192062","75995982543764003382939960430245009492"]},"signature_type":"Line","source":"https://github.com/elastic/elasticsearch/commit/e34ace04b64e9bfa3f9e785b08e6d81f8efe314b"},{"id":"CVE-2025-37731-ef293944","signature_version":"v1","deprecated":false,"target":{"function":"getLength","file":"libs/ssl-config/src/main/java/org/elasticsearch/common/ssl/DerParser.java"},"digest":{"function_hash":"87673803415819436679596541002810312405","length":533},"signature_type":"Function","source":"https://github.com/elastic/elasticsearch/commit/50f58de526b746a6cc07f0cbec0e0d510f13ce52"},{"id":"CVE-2025-37731-f2bd0a10","signature_version":"v1","deprecated":false,"target":{"function":"testSubobjectsAutoFlattened","file":"server/src/test/java/org/elasticsearch/index/mapper/DynamicTemplatesTests.java"},"digest":{"function_hash":"306893537618400629584646210525991294650","length":1526},"signature_type":"Function","source":"https://github.com/elastic/elasticsearch/commit/ed771e6976fac1a085affabd45433234a4babeaf"},{"id":"CVE-2025-37731-f68b2a56","signature_version":"v1","deprecated":false,"target":{"function":"testRootSubobjectAutoDynamicNested","file":"server/src/test/java/org/elasticsearch/index/mapper/DynamicTemplatesTests.java"},"digest":{"function_hash":"199200397922336738803696541874651735467","length":880},"signature_type":"Function","source":"https://github.com/elastic/elasticsearch/commit/ed771e6976fac1a085affabd45433234a4babeaf"},{"id":"CVE-2025-37731-fd0a91ad","signature_version":"v1","deprecated":false,"target":{"function":"addDynamic","file":"server/src/main/java/org/elasticsearch/index/mapper/ObjectMapper.java"},"digest":{"function_hash":"299725294747808491893958480671858604852","length":665},"signature_type":"Function","source":"https://github.com/elastic/elasticsearch/commit/ed771e6976fac1a085affabd45433234a4babeaf"}],"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2025-37731.json"}}],"schema_version":"1.7.3","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N"}]}