CLEANSTART-2026-PM36304

See a problem?
Import Source
https://github.com/cleanstart-dev/cleanstart-security-advisories/blob/main/advisories/2026/CLEANSTART-2026-PM36304.json
JSON Data
https://api.osv.dev/v1/vulns/CLEANSTART-2026-PM36304
Upstream
  • CVE-2026-41417
  • CVE-2026-42580
  • CVE-2026-42581
  • CVE-2026-42584
  • CVE-2026-42585
  • ghsa-2c5c-chwr-9hqw
  • ghsa-38f8-5428-x5cv
  • ghsa-72hv-8253-57qq
  • ghsa-f6hv-jmp6-3vwv
  • ghsa-m4cv-j2px-7723
  • ghsa-mj4r-2hfc-f8p6
  • ghsa-pwqr-wmgm-9rr8
Published
2026-05-18T13:15:42.274600Z
Modified
2026-05-21T10:15:09.943828307Z
Summary
Security fixes for CVE-2026-33870, CVE-2026-41417, CVE-2026-42580, CVE-2026-42581, CVE-2026-42584, CVE-2026-42585, ghsa-2c5c-chwr-9hqw, ghsa-38f8-5428-x5cv, ghsa-72hv-8253-57qq, ghsa-f6hv-jmp6-3vwv, ghsa-m4cv-j2px-7723, ghsa-mj4r-2hfc-f8p6, ghsa-pwqr-wmgm-9rr8 applied in versions: 2.19.5-r0, 3.6.0-r4
Details

Multiple security vulnerabilities affect the opensearch package. These issues are resolved in later releases. See references for individual vulnerability details.

References

Affected packages

CleanStart / opensearch

Package

Name
opensearch

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.6.0-r4

Database specific

source
"https://github.com/cleanstart-dev/cleanstart-security-advisories/blob/main/advisories/2026/CLEANSTART-2026-PM36304.json"