A vulnerability in OpenSearch allows attackers to cause Denial of Service (DoS) by submitting complex query_string inputs.
This issue affects all OpenSearch versions below 3.2.0.
[
{
"target": {
"file": "src/test/java/org/opensearch/security/UtilTests.java"
},
"digest": {
"threshold": 0.9,
"line_hashes": [
"337587567066112158846751319490848932766",
"243173086043611887157670314068874849103",
"106225951026862911709734728195754054001",
"156685412093741342926124056873922866848"
]
},
"signature_version": "v1",
"source": "https://github.com/opensearch-project/security/commit/53429a5853085da5258add822f768d248f70e228",
"deprecated": false,
"id": "CVE-2025-9624-08a72808",
"signature_type": "Line"
},
{
"target": {
"file": "src/main/java/org/opensearch/security/support/WildcardMatcher.java",
"function": "from"
},
"digest": {
"length": 705.0,
"function_hash": "322200501526791948964997181698709585593"
},
"signature_version": "v1",
"source": "https://github.com/opensearch-project/security/commit/53429a5853085da5258add822f768d248f70e228",
"deprecated": false,
"id": "CVE-2025-9624-4bb4be62",
"signature_type": "Function"
},
{
"target": {
"file": "src/test/java/org/opensearch/security/UtilTests.java",
"function": "testWildcardMatcherClasses"
},
"digest": {
"length": 1306.0,
"function_hash": "1626779747580519513273760754940738546"
},
"signature_version": "v1",
"source": "https://github.com/opensearch-project/security/commit/53429a5853085da5258add822f768d248f70e228",
"deprecated": false,
"id": "CVE-2025-9624-81dccea6",
"signature_type": "Function"
},
{
"target": {
"file": "src/main/java/org/opensearch/security/support/WildcardMatcher.java"
},
"digest": {
"threshold": 0.9,
"line_hashes": [
"49348481963301136246504611664912369213",
"120217354522916930801294791257273832661",
"270107619082542973782573518277226409638",
"226764507510670630840363062915672452737"
]
},
"signature_version": "v1",
"source": "https://github.com/opensearch-project/security/commit/53429a5853085da5258add822f768d248f70e228",
"deprecated": false,
"id": "CVE-2025-9624-ddfc0d62",
"signature_type": "Line"
}
]