All 6 CVE vulnerabilities found in OpenSearch, with AI-generated Chinese analysis, references, and POCs.
Vendor: opensearch-project
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2026-18428 | SQL Query Validation Bypass in OpenSearch Direct Query CWE-693 | 8.8 | High | 2026-08-13 |
| CVE-2026-18952 | Missing Input Validation in Threat Intel Feed Parser in OpenSearch Security Analytics Plugin CWE-918 | 8.1 | High | 2026-08-12 |
| CVE-2026-19311 | Missing Authorization in Execute Monitor API in OpenSearch Alerting Plugin CWE-475 | 8.1 | High | 2026-08-12 |
| CVE-2025-9624 | OpenSearch 3.2.0 - Nested Boolean/Disjunction asymmetric DoS CWE-674 | 7.5AI | High AI | 2025-11-25 |
| CVE-2024-54160 | OpenSearch Dashboards Reports 安全漏洞 CWE-79 | 6.4 | Medium | 2025-02-12 |
| CVE-2022-41917 | Incorrect Error Handling Allowed Partial File Reads Over REST API in OpenSearch CWE-200 | 4.3 | Medium | 2022-11-15 |
All 6 known CVE vulnerabilities affecting OpenSearch with full Chinese analysis, references, and POCs where available.