A vulnerability in OpenSearch allows attackers to cause Denial of Service (DoS) by submitting complex query_string inputs.
This issue affects all OpenSearch versions between 3.0.0 and < 3.3.0 and OpenSearch < 2.19.4.
{
"cna_assigner": "Fluid Attacks",
"cwe_ids": [
"CWE-674"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/9xxx/CVE-2025-9624.json"
}{
"cpe": "cpe:2.3:a:amazon:opensearch:*:*:*:*:*:*:*:*",
"extracted_events": [
{
"introduced": "0"
},
{
"fixed": "3.3.0"
}
],
"source": "CPE_RANGE"
}
{
"extracted_events": [
{
"introduced": "3.0.0"
},
{
"fixed": "3.3.0"
},
{
"introduced": "1.0.0"
},
{
"fixed": "2.19.4"
}
],
"source": "AFFECTED_FIELD"
}
{
"cpe": "cpe:2.3:a:amazon:opensearch:*:*:*:*:*:*:*:*",
"extracted_events": [
{
"introduced": "0"
},
{
"fixed": "3.3.0"
}
],
"source": "CPE_RANGE"
}
{
"cpe": "cpe:2.3:a:amazon:opensearch:*:*:*:*:*:*:*:*",
"extracted_events": [
{
"introduced": "0"
},
{
"fixed": "3.3.0"
}
],
"source": "CPE_RANGE"
}
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-9624.json"
[
{
"deprecated": false,
"digest": {
"line_hashes": [
"337587567066112158846751319490848932766",
"243173086043611887157670314068874849103",
"106225951026862911709734728195754054001",
"156685412093741342926124056873922866848"
],
"threshold": 0.9
},
"id": "CVE-2025-9624-08a72808",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/opensearch-project/security/commit/53429a5853085da5258add822f768d248f70e228",
"target": {
"file": "src/test/java/org/opensearch/security/UtilTests.java"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "322200501526791948964997181698709585593",
"length": 705
},
"id": "CVE-2025-9624-4bb4be62",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/opensearch-project/security/commit/53429a5853085da5258add822f768d248f70e228",
"target": {
"file": "src/main/java/org/opensearch/security/support/WildcardMatcher.java",
"function": "from"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "1626779747580519513273760754940738546",
"length": 1306
},
"id": "CVE-2025-9624-81dccea6",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/opensearch-project/security/commit/53429a5853085da5258add822f768d248f70e228",
"target": {
"file": "src/test/java/org/opensearch/security/UtilTests.java",
"function": "testWildcardMatcherClasses"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"49348481963301136246504611664912369213",
"120217354522916930801294791257273832661",
"270107619082542973782573518277226409638",
"226764507510670630840363062915672452737"
],
"threshold": 0.9
},
"id": "CVE-2025-9624-ddfc0d62",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/opensearch-project/security/commit/53429a5853085da5258add822f768d248f70e228",
"target": {
"file": "src/main/java/org/opensearch/security/support/WildcardMatcher.java"
}
}
]
"2026-08-12T15:32:41Z"