A Prototype pollution vulnerability in Kibana leads to arbitrary code execution via crafted HTTP requests to machine learning and reporting endpoints.
[
{
"deprecated": false,
"id": "CVE-2025-25014-2056b06f",
"source": "https://github.com/elastic/elasticsearch/commit/dbcbbbd0bc4924cfeb28929dc05d82d662c527b7",
"digest": {
"function_hash": "155988868032570604689205509621145303938",
"length": 826.0
},
"target": {
"function": "guessMappingsAndCalculateFieldStats",
"file": "x-pack/plugin/text-structure/src/main/java/org/elasticsearch/xpack/textstructure/structurefinder/TextStructureUtils.java"
},
"signature_type": "Function",
"signature_version": "v1"
},
{
"deprecated": false,
"id": "CVE-2025-25014-2d075337",
"source": "https://github.com/elastic/elasticsearch/commit/dbcbbbd0bc4924cfeb28929dc05d82d662c527b7",
"digest": {
"line_hashes": [
"103062777601327816001532191706242182431",
"211766124421928476690457691246930073396",
"109357362993875544563704018619993770016"
],
"threshold": 0.9
},
"target": {
"file": "x-pack/plugin/text-structure/src/test/java/org/elasticsearch/xpack/textstructure/structurefinder/TextStructureUtilsTests.java"
},
"signature_type": "Line",
"signature_version": "v1"
},
{
"deprecated": false,
"id": "CVE-2025-25014-6f51145d",
"source": "https://github.com/elastic/elasticsearch/commit/dbcbbbd0bc4924cfeb28929dc05d82d662c527b7",
"digest": {
"line_hashes": [
"106213297097279866768185910228201675810",
"314168248095395219328740139850914297886",
"119162934123016417405811605557729668362",
"39859272969510159055531249577201918212",
"244933187160039656490785231674378323577",
"234077450779033024857046981396487847380",
"93436833372906784425240664014202993134",
"202381044633269865317511751622544903898",
"254831802349912243738659411130675016589",
"120183324559202470104653390017387002778",
"180925524410113248638112654699035780330",
"102344227782104906477873574944152304516"
],
"threshold": 0.9
},
"target": {
"file": "x-pack/plugin/text-structure/src/main/java/org/elasticsearch/xpack/textstructure/structurefinder/TextStructureUtils.java"
},
"signature_type": "Line",
"signature_version": "v1"
},
{
"deprecated": false,
"id": "CVE-2025-25014-cf8bab70",
"source": "https://github.com/elastic/elasticsearch/commit/dbcbbbd0bc4924cfeb28929dc05d82d662c527b7",
"digest": {
"function_hash": "66582372798516181147542140247763769422",
"length": 1112.0
},
"target": {
"function": "guessMappingAndCalculateFieldStats",
"file": "x-pack/plugin/text-structure/src/main/java/org/elasticsearch/xpack/textstructure/structurefinder/TextStructureUtils.java"
},
"signature_type": "Function",
"signature_version": "v1"
}
]