# Impact of CVE-2025-46295

**URL:** <https://discuss.elastic.co/t/impact-of-cve-2025-46295/384442>\
**Category:** Elastic Security\
**Created:** [January 8, 2026, 2:40pm UTC](https://discuss.elastic.co/t/impact-of-cve-2025-46295/384442 "2026-01-08T14:40:49Z")\
**Posts on this page:** 1\
**Page:** 1

<div class="post-metadata">

**Author:** ![Max-KI](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/max-ki/32/146617_2.png) [@Max-KI](https://discuss.elastic.co/u/Max-KI)\
**Post date:** [January 8, 2026, 2:40pm UTC](https://discuss.elastic.co/t/impact-of-cve-2025-46295/384442/1 "2026-01-08T14:40:49Z")

</div>

# CVE-2025-46295

I just downloaded elastic-9.2.3 for Windows. Our security scanner is flagging it because _commons-text-1.4.jar_ is found in the directory _elasticsearch-9.2.3\modules\x-pack-inference_, and **CVE-2025-46295** has not been fixed in this version. Is this a problem, or can we ignore it?
