# Kibana docker images security

**URL:** <https://discuss.elastic.co/t/kibana-docker-images-security/380910>\
**Category:** Kibana\
**Tags:** docker\
**Created:** [August 8, 2025, 6:39pm UTC](https://discuss.elastic.co/t/kibana-docker-images-security/380910 "2025-08-08T18:39:01Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![smashley](https://avatars.discourse-cdn.com/v4/letter/s/6a8cbe/32.png) [@smashley](https://discuss.elastic.co/u/smashley)\
**Post date:** [August 8, 2025, 6:39pm UTC](https://discuss.elastic.co/t/kibana-docker-images-security/380910/1 "2025-08-08T18:39:01Z")

</div>

I’m running several ES clusters and my Kibana containers are getting flagged for CVE-2025-7783 due to the presence of form-data library. I’ve checked the most recent 8.18.4 and 9.0.4 docker images and they both contain vulnerable versions of this (form-data \<4.0.4). I’ve tried running os patching in the containers but this doesn’t sort it and npm isn’t installed. I checked the security announcements pages but didn’t see anything referencing this vulnerability.

Questions:

1. Are there plans to address this in official images (preferably back-ported to 8.18.0/9.0.0 at least)?

1. Is there an easy way to mitigate by running a few commands in a dockerfile? I’m not familiar with node packages and how to update them.

EDIT: As I poke around I suspect this may be due to an older version of axios in play with a dependency on form-data rather than form-data directly

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [August 8, 2025, 6:47pm UTC](https://discuss.elastic.co/t/kibana-docker-images-security/380910/2 "2025-08-08T18:47:03Z")

</div>

You need to contact elastic through the email [security@elastic.co](mailto:security@elastic.co).

You cannot update the node used by Kibana without possible breaking it, this updated needs to be done by Elastic.

---

<div class="post-metadata">

**Author:** ![smashley](https://avatars.discourse-cdn.com/v4/letter/s/6a8cbe/32.png) [@smashley](https://discuss.elastic.co/u/smashley)\
**Post date:** [August 8, 2025, 6:57pm UTC](https://discuss.elastic.co/t/kibana-docker-images-security/380910/3 "2025-08-08T18:57:30Z")

</div>

Thanks, I’ll do that now. I’d hoped someone would have already called it out as it has been around for a little while now.

---

<div class="post-metadata">

**Author:** ![smashley](https://avatars.discourse-cdn.com/v4/letter/s/6a8cbe/32.png) [@smashley](https://discuss.elastic.co/u/smashley)\
**Post date:** [August 11, 2025, 12:42pm UTC](https://discuss.elastic.co/t/kibana-docker-images-security/380910/4 "2025-08-11T12:42:28Z")

</div>

Circling back for anyone else who might stumble across this, this actually _is_ in a KB article, and now I know where to look next time:

> **[Elastic Support Hub](https://support.elastic.co/knowledge/security-ESST-21cb8ae0-300a-4e49-9fd1-c6389d752794)**

---

<div class="post-metadata">

**Author:** ![Joel\_Andritsch](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/joel_andritsch/32/144600_2.png) [@Joel\_Andritsch](https://discuss.elastic.co/u/Joel_Andritsch)\
**Post date:** [August 12, 2025, 1:52pm UTC](https://discuss.elastic.co/t/kibana-docker-images-security/380910/5 "2025-08-12T13:52:11Z")

</div>

Thank you for following up with a link to the KB. Greatly appreciated!
