opensearch
Top products
Latest CVEs
The 15 most recently published vulnerabilities affecting opensearch.
- CVE-2026-84942Stored Cross-Site Scripting via Vega Expression Function Bypass in OpenSearch Dashboards8.7
- CVE-2026-83497Unrestricted Java Deserialization in OpenSearch SQL Plugin Cursor Pagination8.8
- CVE-2026-77811Stored Cross-Site Scripting via Integration Template Asset in OpenSearch Dashboards8.7
- CVE-2026-18420RCE via Prototype Pollution in OpenSearch Dashboards8.8
- CVE-2026-75897Uncontrolled Resource Consumption in Capabilities Route in OpenSearch Dashboards7.5
- CVE-2025-9624OpenSearch 3.2.0 - Nested Boolean/Disjunction asymmetric DoS7.5
- CVE-2024-39900OpenSearch Dashboards Reports does not properly restrict access to private tenant resources5.4
- CVE-2024-39901OpenSearch Observability does not properly restrict access to private tenant resources4.2
- CVE-2023-33201Bouncy Castle For Java before 1.74 is affected by an LDAP injection vulnerability. The vulnerability only affects applications that use an LDAP CertStore from Bouncy Castle to validate X.509 certif...5.3
- CVE-2023-34455snappy-java's unchecked chunk length leads to DoS7.5
- CVE-2023-34454snappy-java's Integer Overflow vulnerability in compress leads to DoS5.9
- CVE-2023-34453snappy-java's Integer Overflow vulnerability in shuffle leads to DoS5.9
- CVE-2023-2976Use of temporary directory for file creation in `FileBackedOutputStream` in Guava5.5
- CVE-2022-1471Remote Code execution in SnakeYAML8.3
- CVE-2022-34169Apache Xalan Java XSLT library is vulnerable to an integer truncation issue when processing malicious XSLT stylesheets7.5