Opensearch Opensearch

Don't miss out!

Thousands of developers use stack.watch to stay informed.
Get an email whenever new security vulnerabilities are reported in any Opensearch product.

RSS Feeds for Opensearch security vulnerabilities

Create a CVE RSS feed including security vulnerabilities found in Opensearch products with stack.watch. Just hit watch, then grab your custom RSS feed url.

Products by Opensearch Sorted by Most Security Vulnerabilities since 2018

Opensearch3 vulnerabilities

Opensearch Dashboards3 vulnerabilities

Opensearch Observability2 vulnerabilities

By the Year

In 2026 there have been 5 vulnerabilities in Opensearch with an average score of 8.5 out of ten. Last year, in 2025 Opensearch had 1 security vulnerability published. That is, 4 more vulnerabilities have already been reported in 2026 as compared to last year.




Year Vulnerabilities Average Score
2026 5 8.50
2025 1 0.00
2024 2 5.40
2023 0 0.00
2022 1 8.80

It may take a day or so for new Opensearch vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.

Recent Opensearch Security Vulnerabilities

CVE Date Vulnerability Products
CVE-2026-84942 Sep 08, 2026
Improper input validation in the Vega expression function implementation in OpenSearch Dashboards Improper input validation in the Vega expression function implementation in OpenSearch Dashboards allows a remote authenticated actor with dashboard write permissions to execute arbitrary JavaScript in the context of other users' browser sessions by saving a crafted Vega visualization. The checkForFunctionProperty validation routine failed to recurse into arrays of objects, allowing a function property nested inside an array to bypass validation.
Opensearch Dashboards
CVE-2026-83497 Aug 31, 2026
OpenSearch SQL Cursor Pagination Unrestricted Deserialization RCE Unrestricted deserialization of untrusted data in the cursor pagination component in the OpenSearch SQL plugin allows a remote authenticated user with basic read/search permissions to execute arbitrary code on the server by sending a crafted cursor parameter to the plugins/sql endpoint.
Opensearch
CVE-2026-77811 Aug 21, 2026
OpenSearch Dashboards XSS via dashboardsobservability plugin Improper input validation in the dashboards-observability plugin in OpenSearch Dashboards allows a remote authenticated user with write permissions to OpenSearch Dashboards saved objects to execute arbitrary JavaScript in the context of other users' browser sessions by uploading a saved asset with arbitrary web content.
Opensearch Dashboards Dashboards Observability Plugin
CVE-2026-18420 Aug 20, 2026
OpenSearch Dashboards 3.8 TVBZ RCE via JSON (Prototype Pollution) Improper input validation in the Time Series Visual Builder (TSVB) plugin in OpenSearch Dashboards allows an authenticated remote user to execute arbitrary code on the server via a crafted JSON payload to the metrics visualization API endpoint. This issue is a form of prototype pollution that enables remote code execution.  To remediate this issue, users should upgrade to OpenSearch Dashboards 3.8 or later.
Opensearch Dashboards
CVE-2026-75897 Aug 18, 2026
OpenSearch Dashboards Capabilities Route Unbounded Payload DOS Improper input validation in the capabilities route handler in OpenSearch Dashboards - the size of the request payload is not bounded - might allow remote attackers to cause a denial of service via a crafted HTTP request.
Opensearch Dashboards
CVE-2025-9624 Nov 25, 2025
OpenSearch DoS via query_string Before v3.2 A vulnerability in OpenSearch allows attackers to cause Denial of Service (DoS) by submitting complex query_string inputs. This issue affects all OpenSearch versions between 3.0.0 and < 3.3.0 and OpenSearch < 2.19.4.
Opensearch
CVE-2024-39901 Jul 09, 2024
OpenSearch Observability Plugin Data Leak <2.14 OpenSearch Observability is collection of plugins and applications that visualize data-driven events. An issue in the OpenSearch observability plugins allows unintended access to private tenant resources like notebooks. The system did not properly check if the user was the resource author when accessing resources in a private tenant, leading to potential data being revealed. The patches are included in OpenSearch 2.14.
Observability
CVE-2024-39900 Jul 09, 2024
OpenSearch Dashboards Reports Unchecked Tenant Access (2.13) OpenSearch Dashboards Reports allows Report Owner export and share reports from OpenSearch Dashboards. An issue in the OpenSearch reporting plugin allows unintended access to private tenant resources like notebooks. The system did not properly check if the user was the resource author when accessing resources in a private tenant, leading to potential data being revealed. The patches are included in OpenSearch 2.14.
Observability
CVE-2022-31115 Jun 30, 2022
opensearch-ruby is a community-driven, open source fork of elasticsearch-ruby opensearch-ruby is a community-driven, open source fork of elasticsearch-ruby. In versions prior to 2.0.1 the ruby `YAML.load` function was used instead of `YAML.safe_load`. As a result opensearch-ruby 2.0.0 and prior can lead to unsafe deserialization using YAML.load if the response is of type YAML. An attacker must be in control of an opensearch server and convince the victim to connect to it in order to exploit this vulnerability. The problem has been patched in opensearch-ruby gem version 2.0.1. Users are advised to upgrade. There are no known workarounds for this issue.
Opensearch
Built by Foundeo Inc., with data from the National Vulnerability Database (NVD). Privacy Policy. Use of this site is governed by the Legal Terms
Disclaimer
CONTENT ON THIS WEBSITE IS PROVIDED ON AN "AS IS" BASIS AND DOES NOT IMPLY ANY KIND OF GUARANTEE OR WARRANTY, INCLUDING THE WARRANTIES OF MERCHANTABILITY OR FITNESS FOR A PARTICULAR USE. YOUR USE OF THE INFORMATION ON THE DOCUMENT OR MATERIALS LINKED FROM THE DOCUMENT IS AT YOUR OWN RISK. Always check with your vendor for the most up to date, and accurate information.