Opensearch
7 CVEs tracked since 2021. Since Apr 2021, none of them reached CISA KEV.
Opensearch CVEs per month
| Month | CVEs | In CISA KEV |
|---|---|---|
| 2021-04 | 3 | 0 |
| 2021-05 | null or fewer | |
| 2021-06 | null or fewer | |
| 2021-07 | null or fewer | |
| 2021-08 | null or fewer | |
| 2021-09 | null or fewer | |
| 2021-10 | null or fewer | |
| 2021-11 | null or fewer | |
| 2021-12 | null or fewer | |
| 2022-01 | null or fewer | |
| 2022-02 | null or fewer | |
| 2022-03 | null or fewer | |
| 2022-04 | null or fewer | |
| 2022-05 | null or fewer | |
| 2022-06 | null or fewer | |
| 2022-07 | null or fewer | |
| 2022-08 | null or fewer | |
| 2022-09 | null or fewer | |
| 2022-10 | null or fewer | |
| 2022-11 | null or fewer | |
| 2022-12 | null or fewer | |
| 2023-01 | null or fewer | |
| 2023-02 | null or fewer | |
| 2023-03 | null or fewer | |
| 2023-04 | null or fewer | |
| 2023-05 | null or fewer | |
| 2023-06 | 4 | 0 |
Products
The products that kept showing up in Opensearch's monthly top three, with their CVEs summed over those months.
Latest CVEs
The 15 most recently published vulnerabilities affecting Opensearch.
- CVE-2026-84942Stored Cross-Site Scripting via Vega Expression Function Bypass in OpenSearch Dashboards8.7
- CVE-2026-83497Unrestricted Java Deserialization in OpenSearch SQL Plugin Cursor Pagination8.8
- CVE-2026-77811Stored Cross-Site Scripting via Integration Template Asset in OpenSearch Dashboards8.7
- CVE-2026-18420RCE via Prototype Pollution in OpenSearch Dashboards8.8
- CVE-2026-75897Uncontrolled Resource Consumption in Capabilities Route in OpenSearch Dashboards7.5
- CVE-2025-9624OpenSearch 3.2.0 - Nested Boolean/Disjunction asymmetric DoS7.5
- CVE-2024-39900OpenSearch Dashboards Reports does not properly restrict access to private tenant resources5.4
- CVE-2024-39901OpenSearch Observability does not properly restrict access to private tenant resources4.2
- CVE-2023-33201Bouncy Castle For Java before 1.74 is affected by an LDAP injection vulnerability. The vulnerability only affects applications that use an LDAP CertStore from Bouncy Castle to validate X.509 certif...5.3
- CVE-2023-34455snappy-java's unchecked chunk length leads to DoS7.5
- CVE-2023-34454snappy-java's Integer Overflow vulnerability in compress leads to DoS5.9
- CVE-2023-34453snappy-java's Integer Overflow vulnerability in shuffle leads to DoS5.9
- CVE-2023-2976Use of temporary directory for file creation in `FileBackedOutputStream` in Guava5.5
- CVE-2022-1471Remote Code execution in SnakeYAML8.3
- CVE-2022-34169Apache Xalan Java XSLT library is vulnerable to an integer truncation issue when processing malicious XSLT stylesheets7.5
The record
- Peak rank
- #165 in Apr 2021
- Busiest month shown
- Jun 2023, 4 CVEs
- Months with a KEV entry
- 0 since Apr 2021
- Monthly snapshots
- 2 since 2021