CVE List

CVE-2025-9624

Critical 7.5

A vulnerability in OpenSearch allows attackers to cause Denial of Service (DoS) by submitting complex query_string inputs. This issue affects all OpenSearch versions below 3.2.0.

Published November 25, 2025.

Affected software

Get alerts for Amazon Opensearch

Reference links