Denial of Service Vulnerability in OpenSearch by Amazon Web Services
CVE-2025-9624
8.3HIGH
What is CVE-2025-9624?
A security vulnerability in OpenSearch enables malicious actors to execute Denial of Service attacks by manipulating complex query_string inputs. This flaw poses a significant risk to the integrity and availability of services utilizing OpenSearch, especially in versions prior to 3.2.0. Organizations using affected versions should prioritize updating to mitigate potential disruptions.
Affected Version(s)
OpenSearch Windows 3.0.0 < 3.3.0
OpenSearch Windows 1.0.0 < 2.19.4
