Opensearch
Vendor:
First CVE: Jun 30, 2022 · Active for 4 years
11
Total CVEs
More Total CVEs than 89% of tracked products
3.7
Avg CVEs / Year
Higher CVE frequency than 83% of tracked products
6.4
Avg CVSS
Higher Avg CVSS than 28% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Opensearch over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jun 30, 2022
4 years ago
Most Recent CVE
Nov 25, 2025
241 days ago
CVE Severity & Scoring
Opensearch11 CVEs
64%
36%
All CVEs352,294 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local0 (0.0%)
Network11 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low10 (90.9%)
High1 (9.1%)
Unknown0 (0.0%)
User Interaction
None10 (90.9%)
Unknown0 (0.0%)
Required1 (9.1%)
Privileges Required
Low6 (54.5%)
High0 (0.0%)
None5 (45.5%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (11 CVEs).
11 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-31115HIGH opensearch-ruby is a community-driven, open source fork of elasticsearch-ruby. In versions prior to 2.0.1 the ruby `YAML.load` function was used instead of `YAML.safe_load`. As a r | Jun 30, 2022 | 8.8 | 28 | NO | NO |
CVE-2025-9624HIGH A vulnerability in OpenSearch allows attackers to cause Denial of Service (DoS) by submitting complex query_string inputs.
This issue affects all OpenSearch versions between 3.0 | Nov 25, 2025 | 7.5 | 25 | NO | NO |
CVE-2022-35980HIGH OpenSearch Security is a plugin for OpenSearch that offers encryption, authentication and authorization. Versions 2.0.0.0 and 2.1.0.0 of the security plugin are affected by an info | Aug 12, 2022 | 7.5 | 25 | NO | NO |
CVE-2023-23612HIGH OpenSearch is an open source distributed and RESTful search engine. OpenSearch uses JWTs to store role claims obtained from the Identity Provider (IdP) when the authentication back | Jan 26, 2023 | 8.8 | 22 | NO | NO |
CVE-2022-41918MEDIUM OpenSearch is a community-driven, open source fork of Elasticsearch and Kibana. There is an issue with the implementation of fine-grained access control rules (document-level secur | Nov 15, 2022 | 6.3 | 22 | NO | NO |
CVE-2023-23613MEDIUM OpenSearch is an open source distributed and RESTful search engine. In affected versions there is an issue in the implementation of field-level security (FLS) and field masking whe | Jan 26, 2023 | 6.5 | 21 | NO | NO |
CVE-2023-45807MEDIUM OpenSearch is a community-driven, open source fork of Elasticsearch and Kibana following the license change in early 2021. There is an issue with the implementation of tenant permi | Oct 16, 2023 | 5.4 | 19 | NO | NO |
CVE-2023-25806MEDIUM OpenSearch Security is a plugin for OpenSearch that offers encryption, authentication and authorization. There is an observable discrepancy in the authentication response time betw | Mar 2, 2023 | 5.3 | 18 | NO | NO |
CVE-2022-41917MEDIUM OpenSearch is a community-driven, open source fork of Elasticsearch and Kibana. OpenSearch allows users to specify a local file when defining text analyzers to process data for tex | Nov 16, 2022 | 4.3 | 18 | NO | NO |
CVE-2023-23933MEDIUM OpenSearch Anomaly Detection identifies atypical data and receives automatic notifications. There is an issue with the application of document and field level restrictions in the A | Feb 3, 2023 | 4.3 | 17 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (11 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (11 CVEs).
Media Mentions
Signals from CVEs in this product scope (11 CVEs).
Top CNAs Publishing CVEs For Opensearch
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 2.1.0 | 1 | 7.5 | 0.9% | 0 | 0 |
| 2.0.0 | 1 | 7.5 | 0.9% | 0 | 0 |