HIGH
GHSA-mw3v-mmfw-3x2g
OpenSearch is vulnerable to DoS via complex query_string inputs
Quick fix
GHSA-mw3v-mmfw-3x2g — org.opensearch:opensearch-common: upgrade to the fixed version with the command below.
# pom.xml: bump <version>3.3.0</version> for org.opensearch:opensearch-commonDetails
A vulnerability in OpenSearch allows attackers to cause Denial of Service (DoS) by submitting complex query_string inputs.
This issue affects all OpenSearch versions below 2.19.4 and versions 3.0.0 through 3.2.0.
Are you affected?
Enter the version of the package you're using.
Affected packages
Maven/org.opensearch:opensearch-common
Introduced in:
3.0.0Fixed in: 3.3.0Fix
# pom.xml: bump <version>3.3.0</version> for org.opensearch:opensearch-commonMaven/org.opensearch:opensearch-common
Introduced in:
0Fixed in: 2.19.4Fix
# pom.xml: bump <version>2.19.4</version> for org.opensearch:opensearch-commonReferences
- https://nvd.nist.gov/vuln/detail/CVE-2025-9624[ADVISORY]
- https://github.com/opensearch-project/OpenSearch/pull/19491[WEB]
- https://caverav.cl/posts/opensearch-dos/opensearch-dos[WEB]
- https://fluidattacks.com/advisories/chick[WEB]
- https://github.com/opensearch-project/OpenSearch[PACKAGE]
- https://github.com/opensearch-project/OpenSearch/releases/tag/2.19.4[WEB]
- https://github.com/opensearch-project/OpenSearch/releases/tag/3.3.0[WEB]
- https://opensearch.org/blog/explore-opensearch-3-3[WEB]