CVE 8.3 HIGH

OpenSearch 3.2.0 – Nested Boolean/Disjunction asymmetric DoS_CVE-2025-9624

8.3 / 10
HIGH
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H

Description

A vulnerability in OpenSearch allows attackers to cause Denial of Service (DoS) by submitting complex query_string inputs.



This issue affects all OpenSearch versions below 3.2.0.

Basic Information

ID CVE-2025-9624
Source Fluid Attacks
Published Nov 25, 2025 at 19:43
Modified Nov 25, 2025 at 21:03

Affected Product

Vendor OpenSearch
Product OpenSearch
Version 1.0.0
Affected Versions OpenSearch OpenSearch 1.0.0

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.