Amazon Opensearch Service Aws Amazon Opensearch Service

Don't miss out!

Thousands of developers use stack.watch to stay informed.
Get an email whenever new security vulnerabilities are reported in Aws Amazon Opensearch Service.

By the Year

In 2026 there have been 2 vulnerabilities in Aws Amazon Opensearch Service with an average score of 8.2 out of ten.

Year Vulnerabilities Average Score
2026 2 8.15

It may take a day or so for new Amazon Opensearch Service vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.

Recent Aws Amazon Opensearch Service Security Vulnerabilities

OpenSearch Dashboards 3.8 TVBZ RCE via JSON (Prototype Pollution)
CVE-2026-18420 8.8 - High - August 20, 2026

Improper input validation in the Time Series Visual Builder (TSVB) plugin in OpenSearch Dashboards allows an authenticated remote user to execute arbitrary code on the server via a crafted JSON payload to the metrics visualization API endpoint. This issue is a form of prototype pollution that enables remote code execution.  To remediate this issue, users should upgrade to OpenSearch Dashboards 3.8 or later.

Prototype Pollution

OpenSearch Dashboards Capabilities Route Unbounded Payload DOS
CVE-2026-75897 7.5 - High - August 18, 2026

Improper input validation in the capabilities route handler in OpenSearch Dashboards - the size of the request payload is not bounded - might allow remote attackers to cause a denial of service via a crafted HTTP request.

Improper Validation of Specified Quantity in Input

Stay on top of Security Vulnerabilities

Want an email whenever new vulnerabilities are published for Aws Amazon Opensearch Service or by Aws? Click the Watch button to subscribe.

Aws
Vendor

subscribe