CVE-2025-35434: exploitation status and patch state
CVE-2025-35434 · CVSS 4.2 MEDIUM · EPSS <1%
CISA Thorium does not validate TLS certificates when connecting to Elasticsearch. An unauthenticated attacker with access to a Thorium cluster could impersonate the Elasticsearch service. Fixed in 1.1.2.
Is CVE-2025-35434 exploited?
Not in the CISA KEV catalog.
EPSS puts exploitation in the next 30 days at <1%.
Public exploit code: none found in monitored sources.