CVE Tools

Opensearch

7 CVEs tracked since 2021. Since Apr 2021, none of them reached CISA KEV.

Opensearch CVEs per month

Apr 2021 to Jun 2023. Point at a month, or focus the strip and use the arrow keys.
Opensearch CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2021-0430
2021-05null or fewer
2021-06null or fewer
2021-07null or fewer
2021-08null or fewer
2021-09null or fewer
2021-10null or fewer
2021-11null or fewer
2021-12null or fewer
2022-01null or fewer
2022-02null or fewer
2022-03null or fewer
2022-04null or fewer
2022-05null or fewer
2022-06null or fewer
2022-07null or fewer
2022-08null or fewer
2022-09null or fewer
2022-10null or fewer
2022-11null or fewer
2022-12null or fewer
2023-01null or fewer
2023-02null or fewer
2023-03null or fewer
2023-04null or fewer
2023-05null or fewer
2023-0640

Products

The products that kept showing up in Opensearch's monthly top three, with their CVEs summed over those months.

  1. Logstash72 months

Latest CVEs

The 15 most recently published vulnerabilities affecting Opensearch.

  1. CVE-2026-84942Stored Cross-Site Scripting via Vega Expression Function Bypass in OpenSearch Dashboards8.7
  2. CVE-2026-83497Unrestricted Java Deserialization in OpenSearch SQL Plugin Cursor Pagination8.8
  3. CVE-2026-77811Stored Cross-Site Scripting via Integration Template Asset in OpenSearch Dashboards8.7
  4. CVE-2026-18420RCE via Prototype Pollution in OpenSearch Dashboards8.8
  5. CVE-2026-75897Uncontrolled Resource Consumption in Capabilities Route in OpenSearch Dashboards7.5
  6. CVE-2025-9624OpenSearch 3.2.0 - Nested Boolean/Disjunction asymmetric DoS7.5
  7. CVE-2024-39900OpenSearch Dashboards Reports does not properly restrict access to private tenant resources5.4
  8. CVE-2024-39901OpenSearch Observability does not properly restrict access to private tenant resources4.2
  9. CVE-2023-33201Bouncy Castle For Java before 1.74 is affected by an LDAP injection vulnerability. The vulnerability only affects applications that use an LDAP CertStore from Bouncy Castle to validate X.509 certif...5.3
  10. CVE-2023-34455snappy-java's unchecked chunk length leads to DoS7.5
  11. CVE-2023-34454snappy-java's Integer Overflow vulnerability in compress leads to DoS5.9
  12. CVE-2023-34453snappy-java's Integer Overflow vulnerability in shuffle leads to DoS5.9
  13. CVE-2023-2976Use of temporary directory for file creation in `FileBackedOutputStream` in Guava5.5
  14. CVE-2022-1471Remote Code execution in SnakeYAML8.3
  15. CVE-2022-34169Apache Xalan Java XSLT library is vulnerable to an integer truncation issue when processing malicious XSLT stylesheets7.5

The record

Peak rank
#165 in Apr 2021
Busiest month shown
Jun 2023, 4 CVEs
Months with a KEV entry
0 since Apr 2021
Monthly snapshots
2 since 2021
Opensearch's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store