Source: opensearch Version: 2.4.1+dfsg-2 Severity: important Tags: security upstream X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>
Hi, The following vulnerability was published for opensearch. CVE-2025-9624[0]: | A vulnerability in OpenSearch allows attackers to cause Denial of | Service (DoS) by submitting complex query_string inputs. This | issue affects all OpenSearch versions below 3.2.0. According to the upstream information this should be fixed in the 3.3.0 version onwards. If you fix the vulnerability please also make sure to include the CVE (Common Vulnerabilities & Exposures) id in your changelog entry. For further information see: [0] https://security-tracker.debian.org/tracker/CVE-2025-9624 https://www.cve.org/CVERecord?id=CVE-2025-9624 Regards, Salvatore

