This issue affects all OpenSearch versions between 3.0.0 and < 3.3.0 and OpenSearch < 2.19.4.
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-mw3v-mmfw-3x2g | OpenSearch is vulnerable to DoS via complex query_string inputs |
Mon, 15 Dec 2025 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Mon, 15 Dec 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability in OpenSearch allows attackers to cause Denial of Service (DoS) by submitting complex query_string inputs. This issue affects all OpenSearch versions below 3.2.0. | A vulnerability in OpenSearch allows attackers to cause Denial of Service (DoS) by submitting complex query_string inputs. This issue affects all OpenSearch versions between 3.0.0 and < 3.3.0 and OpenSearch < 2.19.4. |
| References |
|
Tue, 02 Dec 2025 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Amazon
Amazon opensearch |
|
| CPEs | cpe:2.3:a:amazon:opensearch:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Amazon
Amazon opensearch |
|
| Metrics |
cvssV3_1
|
Tue, 25 Nov 2025 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 25 Nov 2025 20:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability in OpenSearch allows attackers to cause Denial of Service (DoS) by submitting complex query_string inputs. This issue affects all OpenSearch versions below 3.2.0. | |
| Title | OpenSearch 3.2.0 - Nested Boolean/Disjunction asymmetric DoS | |
| First Time appeared |
Opensearch
Opensearch opensearch |
|
| Weaknesses | CWE-674 | |
| CPEs | cpe:2.3:a:opensearch:opensearch:*:*:linux:*:*:*:*:* cpe:2.3:a:opensearch:opensearch:*:*:macos:*:*:*:*:* cpe:2.3:a:opensearch:opensearch:*:*:windows:*:*:*:*:* |
|
| Vendors & Products |
Opensearch
Opensearch opensearch |
|
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: Fluid Attacks
Published:
Updated: 2025-12-15T14:04:03.148Z
Reserved: 2025-08-28T19:08:18.437Z
Link: CVE-2025-9624
Updated: 2025-11-25T20:59:33.441Z
Status : Modified
Published: 2025-11-25T20:16:01.177
Modified: 2025-12-15T14:15:57.967
Link: CVE-2025-9624
No data.
OpenCVE Enrichment
No data.
Github GHSA