opensearch-2

Direct Vulnerabilities

Known vulnerabilities in the opensearch-2 package. This does not include vulnerabilities belonging to this package’s dependencies.

Fix vulnerabilities automatically

Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.

Fix for free
VulnerabilityVulnerable Version
  • L
GHSA-hf6x-8p5f-cgmf

<2.19.6-r7
  • L
GHSA-v3jc-474w-2wm6

<2.19.6-r7
  • L
GHSA-hjcp-jmpx-g3qm

<2.19.6-r7
  • L
Missing Release of Resource after Effective Lifetime

<2.19.6-r7
  • L
CVE-2026-54399

<2.19.6-r7
  • L
CVE-2026-54428

<2.19.6-r7
  • L
Cross-site Scripting (XSS)

<2.19.6-r7
  • L
GHSA-pmhh-3w7g-xqp8

<2.19.6-r7
  • L
Missing Release of Resource after Effective Lifetime

<2.19.6-r6
  • L
GHSA-6cqp-g7gg-8hr5

<2.19.6-r6
  • L
Improper Access Control

<2.19.6-r6
  • L
GHSA-mfg7-5gfp-c4w3

<2.19.6-r6
  • L
GHSA-jppx-w49h-x2qq

<2.19.6-r6
  • L
GHSA-gcjf-9mgh-3p7g

<2.19.6-r6
  • L
GHSA-558v-64gr-wgg4

<2.19.6-r6
  • L
GHSA-6jqx-86gh-f27w

<2.19.6-r6
  • L
GHSA-xx22-p4ch-683r

<2.19.6-r6
  • L
GHSA-q4f6-jm68-57ww

<2.19.6-r6
  • H
HTTP Request Smuggling

<2.19.6-r6
  • L
Resource Exhaustion

<2.19.6-r6
  • L
NULL Pointer Dereference

<2.19.6-r6
  • L
GHSA-c69g-56f8-xwqj

<2.19.6-r6
  • L
Resource Exhaustion

<2.19.6-r6
  • L
Resource Exhaustion

<2.19.6-r6
  • H
Loop with Unreachable Exit Condition ('Infinite Loop')

<2.19.6-r6
  • L
GHSA-93wv-jw9v-4972

<2.19.6-r6
  • M
HTTP Request Smuggling

<2.19.6-r6
  • H
Allocation of Resources Without Limits or Throttling

<2.19.6-r6
  • L
GHSA-mvh2-crg5-v77c

<2.19.6-r6
  • M
CRLF Injection

<2.19.6-r6
  • H
Resource Exhaustion

<2.19.6-r6
  • L
GHSA-4mp9-239f-g9hg

<2.19.6-r6
  • L
GHSA-mhm7-754m-9p8w

<2.19.6-r5
  • L
GHSA-5gvw-p9qm-jgwh

<2.19.6-r5
  • L
Incorrect Authorization

<2.19.6-r5
  • L
GHSA-5jmj-h7xm-6q6v

<2.19.6-r5
  • L
Improperly Controlled Modification of Dynamically-Determined Object Attributes

<2.19.6-r5
  • L
CVE-2026-8149

<2.19.6-r0
  • L
GHSA-mx76-r943-rf8g

<2.19.6-r0
  • L
GHSA-hgj6-7826-r7m5

<2.19.6-r2
  • L
Server-Side Request Forgery (SSRF)

<2.19.6-r2
  • L
CVE-2025-14813

<2.19.6-r0
  • L
GHSA-j3rv-43j4-c7qm

<2.19.6-r2
  • L
Incomplete Blacklist

<2.19.6-r2
  • L
Incomplete Blacklist

<2.19.6-r2
  • L
GHSA-rmj7-2vxq-3g9f

<2.19.6-r2
  • L
GHSA-574f-3g2m-x479

<2.19.6-r0
  • H
Improper Encoding or Escaping of Output

<2.19.6-r0
  • L
GHSA-6hg6-v5c8-fphq

<2.19.6-r0
  • L
CVE-2026-5598

<2.19.6-r0
  • L
GHSA-p93r-85wp-75v3

<2.19.6-r0
  • H
Improper Output Neutralization for Logs

<2.19.6-r0
  • L
GHSA-wg6q-6289-32hp

<2.19.6-r0
  • L
GHSA-445c-vh5m-36rj

<2.19.6-r0
  • L
GHSA-c3fc-8qff-9hwx

<2.19.6-r0
  • L
CVE-2026-0636

<2.19.6-r0
  • L
CVE-2026-5588

<2.19.6-r0
  • L
GHSA-3pxv-7cmr-fjr4

<2.19.6-r0
  • M
Improper Validation of Certificate with Host Mismatch

<2.19.6-r0
  • L
GHSA-c653-97m9-rcg9

<2.19.5-r1
  • L
Resource Exhaustion

<2.19.5-r1
  • L
GHSA-5pvg-856g-cp85

<2.19.5-r1
  • L
GHSA-676x-f7gg-47vc

<2.19.5-r1
  • L
Use of Insufficiently Random Values

<2.19.5-r1
  • L
GHSA-x4gw-5cx5-pgmh

<2.19.5-r1
  • C
Insufficient Verification of Data Authenticity

<2.19.5-r1
  • M
Allocation of Resources Without Limits or Throttling

<2.19.5-r1
  • L
GHSA-c2gf-v879-257j

<2.19.5-r1
  • L
GHSA-563q-j3cm-6jxm

<2.19.5-r1
  • L
Allocation of Resources Without Limits or Throttling

<2.19.5-r1
  • L
GHSA-3qp7-7mw8-wx86

<2.19.5-r1
  • L
GHSA-xmv7-r254-6q78

<2.19.5-r1
  • L
GHSA-5x3r-wrvg-rp6q

<2.19.5-r1
  • L
HTTP Request Smuggling

<2.19.5-r1
  • L
Improper Access Control

<2.19.5-r1
  • C
Insufficient Verification of Data Authenticity

<2.19.5-r1
  • L
Improper Verification of Cryptographic Signature

<2.19.5-r1
  • H
Resource Exhaustion

<2.19.5-r1
  • L
GHSA-hvcg-qmg6-jm4c

<2.19.5-r1
  • L
Resource Exhaustion

<2.19.4-r14
  • H
HTTP Response Splitting

<2.19.4-r14
  • H
Improper Encoding or Escaping of Output

<2.19.4-r14
  • L
GHSA-h383-gmxw-35v2

<2.19.4-r14
  • L
GHSA-cm33-6792-r9fm

<2.19.4-r14
  • L
GHSA-45q3-82m4-75jr

<2.19.4-r14
  • L
CRLF Injection

<2.19.4-r14
  • L
GHSA-57rv-r2g8-2cj3

<2.19.4-r14
  • L
GHSA-38f8-5428-x5cv

<2.19.4-r14
  • L
GHSA-xxqh-mfjm-7mv9

<2.19.4-r14
  • L
GHSA-f6hv-jmp6-3vwv

<2.19.4-r14
  • L
GHSA-m4cv-j2px-7723

<2.19.4-r14
  • L
GHSA-mj4r-2hfc-f8p6

<2.19.4-r14
  • L
GHSA-5qcv-4rpc-jp93

<2.19.4-r14
  • L
Integer Overflow or Wraparound

<2.19.4-r14
  • L
GHSA-v8h7-rr48-vmmv

<2.19.4-r14
  • L
Information Exposure Through Server Log Files

<2.19.4-r14
  • L
Race Condition

<2.19.4-r14
  • H
HTTP Request Smuggling

<2.19.4-r14
  • L
Resource Exhaustion

<2.19.4-r14
  • L
GHSA-wf66-mphr-4c4r

<2.19.4-r14
  • C
HTTP Request Smuggling

<2.19.4-r14
  • C
HTTP Request Smuggling

<2.19.4-r14
  • C
Improper Input Validation

<2.19.4-r14
  • L
GHSA-pwqr-wmgm-9rr8

<2.19.4-r13
  • H
Allocation of Resources Without Limits or Throttling

<2.19.4-r13
  • L
GHSA-w9fj-cfpg-grvv

<2.19.4-r13
  • L
HTTP Request Smuggling

<2.19.4-r13
  • M
Improper Certificate Validation

<2.19.4-r12
  • L
GHSA-72hv-8253-57qq

<2.19.4-r12
  • L
GHSA-vc5p-v9hr-52mj

<2.19.4-r12
  • L
CVE-2025-12183

<2.19.4-r12
  • L
Information Exposure

<2.19.4-r12
  • L
GHSA-cmp6-m4wj-q63q

<2.19.4-r12
  • L
GHSA-vqf4-7m7x-wgfc

<2.19.4-r12
  • L
CRLF Injection

<2.19.4-r6
  • L
GHSA-84h7-rjj3-6jx4

<2.19.4-r6
  • H
Improper Handling of Highly Compressed Data (Data Amplification)

<2.19.4-r0
  • L
GHSA-73m2-qfq3-56cx

<2.19.4-r0
  • L
GHSA-fghv-69vj-qj49

<2.19.4-r0
  • L
GHSA-3p8m-j85q-pgmj

<2.19.4-r0
  • L
GHSA-wxr5-93ph-8wr9

<2.19.4-r0
  • L
GHSA-4cx2-fc23-5wg6

<2.19.4-r0
  • L
CVE-2025-27820

<2.19.4-r0
  • L
GHSA-j288-q9x7-2f5v

<2.19.4-r0
  • L
CVE-2024-57699

<2.19.4-r0
  • L
CVE-2025-48734

<2.19.4-r0
  • L
GHSA-pq2g-wx69-c263

<2.19.4-r0
  • L
GHSA-prj3-ccx8-p6x4

<2.19.4-r0
  • L
Uncontrolled Recursion

<2.19.4-r0
  • H
Allocation of Resources Without Limits or Throttling

<2.19.4-r0
  • L
CVE-2025-8916

<2.19.4-r0
  • H
HTTP Request Smuggling

<2.19.4-r0
  • L
GHSA-mw3v-mmfw-3x2g

<2.19.4-r0
  • H
Uncontrolled Recursion

<2.19.4-r0
  • L
XML External Entity (XXE) Injection

<2.19.4-r0
  • L
CVE-2025-27817

<2.19.1-r5
  • L
CVE-2025-31672

<2.19.1-r2
  • L
CVE-2025-24970

<2.19.1-r0
  • L
CVE-2025-0851

<2.19.1-r0
  • H
Out-of-bounds Write

<2.18.0-r0
  • L
Resource Exhaustion

<2.17.1-r1
  • L
CVE-2024-34447

<2.16.0-r0
  • L
CVE-2024-30171

<2.16.0-r0
  • L
CVE-2024-29857

<2.16.0-r0
  • L
CVE-2024-30172

<2.16.0-r0
  • L
CVE-2024-37902

<2.15.0-r0
  • M
Arbitrary Code Injection

<2.14.0-r0
  • L
Server-Side Request Forgery (SSRF)

<2.13.0-r0
  • L
CVE-2024-29025

<2.13.0-r0
  • M
Loop with Unreachable Exit Condition ('Infinite Loop')

<2.12.0-r1
  • M
Allocation of Resources Without Limits or Throttling

<2.12.0-r1
  • M
Use After Free

<2.11.1-r1
  • M
CVE-2023-42503

<2.10.0-r1