# Clarification on CVE / Vulnerability ID related to bundled commons-text-1.4.jar in Elasticsearch 8.19.x

**URL:** <https://discuss.elastic.co/t/clarification-on-cve-vulnerability-id-related-to-bundled-commons-text-1-4-jar-in-elasticsearch-8-19-x/386398>\
**Category:** Elasticsearch\
**Created:** [May 19, 2026, 8:54am UTC](https://discuss.elastic.co/t/clarification-on-cve-vulnerability-id-related-to-bundled-commons-text-1-4-jar-in-elasticsearch-8-19-x/386398 "2026-05-19T08:54:16Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![lukecw](https://avatars.discourse-cdn.com/v4/letter/l/aca169/32.png) [@lukecw](https://discuss.elastic.co/u/lukecw)\
**Post date:** [May 19, 2026, 8:54am UTC](https://discuss.elastic.co/t/clarification-on-cve-vulnerability-id-related-to-bundled-commons-text-1-4-jar-in-elasticsearch-8-19-x/386398/1 "2026-05-19T08:54:16Z")

</div>

Hello,

we need clarification regarding a vulnerability finding raised by our security scanner on Elasticsearch.

The scanner is reporting the following issue:

- **CVE:** `CVE-2025-46295`

- **Vulnerability ID:** `OO0TMV`

On our Elasticsearch nodes we identified the following bundled JAR:

/usr/share/elasticsearch/modules/x-pack-inference/commons-text-1.4.jar

Our current Elasticsearch version is:

8.19.12

From our package repository, we can see that the following newer patch versions are available:

- 8.19.13

- 8.19.14

- 8.19.15

We would like to clarify the following points:

### Questions

1. Is `commons-text-1.4.jar` in `x-pack-inference` an officially bundled dependency shipped with Elasticsearch 8.19.12?

2. Is this component actually affected by **CVE-2025-46295 / Vulnerability ID OO0TMV** in the Elasticsearch context?

3. If yes, has this dependency been updated, removed, or otherwise remediated in:

4. What is the **first Elasticsearch version** in which `commons-text-1.4.jar` is no longer present or is replaced by a remediated version?

5. Is there any official advisory, release note, or remediation guidance that specifically addresses this issue?

6. If the JAR is present but not exploitable in Elasticsearch usage, could you please provide an official statement or explanation that we can share internally with our security team and vulnerability management process?

7. Since this dependency is bundled inside Elasticsearch, can you confirm whether the **only supported remediation path** is upgrading Elasticsearch to a fixed version?

### Additional context

At the moment, our objective is to determine the **minimum Elasticsearch version** we need to upgrade to in order to remediate the finding related to:

- `CVE-2025-46295`

- `Vulnerability ID OO0TMV`

- bundled `commons-text-1.4.jar`

If possible, please provide the exact fixed version and any related documentation we can reference.

Thank you all

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [May 19, 2026, 9:10am UTC](https://discuss.elastic.co/t/clarification-on-cve-vulnerability-id-related-to-bundled-commons-text-1-4-jar-in-elasticsearch-8-19-x/386398/2 "2026-05-19T09:10:24Z")

</div>

Welcome and thank you for your question.

Elastic's security reporting guidelines are available at [Product Security at Elastic | Elastic](https://www.elastic.co/community/security).

Per those guidelines, all reports of potential security issues or vulnerabilities should be sent via email to [security@elastic.co](mailto:security@elastic.co).

We are unable to discuss potential issues of this nature here. Please send your report to the email address above, where it can be appropriately handled.

---

<div class="post-metadata">

**Author:** ![lukecw](https://avatars.discourse-cdn.com/v4/letter/l/aca169/32.png) [@lukecw](https://discuss.elastic.co/u/lukecw)\
**Post date:** [May 19, 2026, 9:19am UTC](https://discuss.elastic.co/t/clarification-on-cve-vulnerability-id-related-to-bundled-commons-text-1-4-jar-in-elasticsearch-8-19-x/386398/4 "2026-05-19T09:19:19Z")

</div>

Thank you for you suggestion.. i'll write a mail to the [security@elastic.com](mailto:security@elastic.com)

Best regards

Luca
