<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – OpenSearch (High+Critical)</title>
  <link>https://cvedaily.com/pages/tags/opensearch.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/opensearch-severe.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – OpenSearch (High+Critical)</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:26:50 +0000</lastBuildDate>
  <item>
    <title>[High] CVE-2026-7191 – Improper use of the static-eval npm package in the open source solution qnabot-o...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-7191</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-7191</guid>
    <pubDate>Mon, 27 Apr 2026 21:16:44 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-7191</strong></p>
  <p>Improper use of the static-eval npm package in the open source solution qnabot-on-aws versions 7.2.4 and earlier may allow an authenticated administrator to execute arbitrary code within the fulfillment Lambda execution context by injecting a crafted conditional chaining expression via the Content Designer interface, which bypasses the intended expression sandbox through JavaScript prototype mani…</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-7191">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-9624 – A vulnerability in OpenSearch allows attackers to cause Denial of Service (DoS) ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-9624</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-9624</guid>
    <pubDate>Tue, 25 Nov 2025 20:16:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-9624</strong></p>
  <p>A vulnerability in OpenSearch allows attackers to cause Denial of Service (DoS) by submitting complex query_string inputs.    This issue affects all OpenSearch versions between 3.0.0 and < 3.3.0 and OpenSearch < 2.19.4.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-674</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-9624">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-62371 – OpenSearch Data Prepper as an open source data collector for observability data...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-62371</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-62371</guid>
    <pubDate>Wed, 15 Oct 2025 18:15:39 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-62371</strong></p>
  <p>OpenSearch Data Prepper as an open source data collector for observability data. In versions prior to 2.12.2, the OpenSearch sink and source plugins in Data Prepper trust all SSL certificates by default when no certificate path is provided. Prior to this fix, the OpenSearch sink and source plugins would automatically use a trust all SSL strategy when connecting to OpenSearch clusters if no certif…</p>
  <p><strong>CVSS:</strong> 7.4 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-62371">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-23671 – Improper Neutralization of Input During Web Page Generation ('Cross-site Scripti...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-23671</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-23671</guid>
    <pubDate>Fri, 31 Jan 2025 09:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-23671</strong></p>
  <p>Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in sav WP OpenSearch wp-opensearch allows Stored XSS.This issue affects WP OpenSearch: from n/a through <= 1.0.</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-23671">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-21545 – Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleS...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-21545</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-21545</guid>
    <pubDate>Tue, 21 Jan 2025 21:15:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-21545</strong></p>
  <p>Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: OpenSearch).  Supported versions that are affected are 8.60 and  8.61. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools.  Successful attacks of this vulnerability can result in unauthorized ability to cause a h…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-400</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-21545">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-41906 – OpenSearch Notifications is a notifications plugin for OpenSearch that enables o...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-41906</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-41906</guid>
    <pubDate>Fri, 11 Nov 2022 19:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-41906</strong></p>
  <p>OpenSearch Notifications is a notifications plugin for OpenSearch that enables other plugins to send notifications via Email, Slack, Amazon Chime, Custom web-hook etc channels. A potential SSRF issue in OpenSearch Notifications Plugin starting in 2.0.0 and prior to 2.2.1 could allow an existing privileged user to enumerate listening services or interact with configured resources via HTTP requests…</p>
  <p><strong>CVSS:</strong> 8.7 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-41906">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-35980 – OpenSearch Security is a plugin for OpenSearch that offers encryption, authentic...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-35980</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-35980</guid>
    <pubDate>Fri, 12 Aug 2022 18:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-35980</strong></p>
  <p>OpenSearch Security is a plugin for OpenSearch that offers encryption, authentication and authorization. Versions 2.0.0.0 and 2.1.0.0 of the security plugin are affected by an information disclosure vulnerability. Requests to an OpenSearch cluster configured with advanced access control features document level security (DLS), field level security (FLS), and/or field masking will not be filtered w…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-612</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-35980">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-31115 – opensearch-ruby is a community-driven, open source fork of elasticsearch-ruby. I...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-31115</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-31115</guid>
    <pubDate>Thu, 30 Jun 2022 22:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-31115</strong></p>
  <p>opensearch-ruby is a community-driven, open source fork of elasticsearch-ruby. In versions prior to 2.0.1 the ruby `YAML.load` function was used instead of `YAML.safe_load`. As a result opensearch-ruby 2.0.0 and prior can lead to unsafe deserialization using YAML.load if the response is of type YAML. An attacker must be in control of an opensearch server and convince the victim to connect to it i…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-502</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-31115">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2021-44833 – The CLI 1.0.0 for Amazon AWS OpenSearch has weak permissions for the configurati...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-44833</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-44833</guid>
    <pubDate>Sun, 12 Dec 2021 06:15:06 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2021-44833</strong></p>
  <p>The CLI 1.0.0 for Amazon AWS OpenSearch has weak permissions for the configuration file.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-276</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-44833">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
