Opensearch Aws Opensearch

Don't miss out!

Thousands of developers use stack.watch to stay informed.
Get an email whenever new security vulnerabilities are reported in Aws Opensearch.

By the Year

In 2026 there have been 2 vulnerabilities in Aws Opensearch with an average score of 8.6 out of ten.

Year Vulnerabilities Average Score
2026 2 8.60

It may take a day or so for new Opensearch vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.

Recent Aws Opensearch Security Vulnerabilities

OpenSearch SecurityAnalytics Plugin SSRF via Unvalidated Threat Intel Feed URL
CVE-2026-18952 8.6 - High - August 12, 2026

Missing input validation in the threat intelligence feed parser in the OpenSearch Security Analytics plugin might allow an authenticated remote user to perform server-side request forgery and read local files via a crafted URL parameter to the threat intel source configuration endpoint.

SSRF

Missing Auth in OpenSearch Execute Monitor API Enables Data Manipulation
CVE-2026-19311 8.6 - High - August 12, 2026

Missing authorization in the Execute Monitor API in Amazon OpenSearch Alerting plugin might allow an authenticated remote user to read, modify, or delete arbitrary index data via a crafted inline monitor request with unintentional data source and input index parameters.

Undefined Behavior for Input to API

Stay on top of Security Vulnerabilities

Want an email whenever new vulnerabilities are published for Aws Opensearch or by Aws? Click the Watch button to subscribe.

Aws
Vendor

subscribe