A vulnerability in OpenSearch allows attackers to cause Denial of Service (DoS) by submitting complex query_string inputs.
This issue affects all OpenSearch versions between 3.0.0 and < 3.3.0 and OpenSearch < 2.19.4.
{
"cwe_ids": [
"CWE-674"
],
"cna_assigner": "Fluid Attacks",
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/9xxx/CVE-2025-9624.json"
}{
"source": "CPE_RANGE",
"cpe": "cpe:2.3:a:amazon:opensearch:*:*:*:*:*:*:*:*",
"extracted_events": [
{
"introduced": "0"
},
{
"fixed": "3.3.0"
}
]
}{
"source": "AFFECTED_FIELD",
"extracted_events": [
{
"introduced": "3.0.0"
},
{
"fixed": "3.3.0"
},
{
"introduced": "1.0.0"
},
{
"fixed": "2.19.4"
}
]
}{
"source": "CPE_RANGE",
"cpe": "cpe:2.3:a:amazon:opensearch:*:*:*:*:*:*:*:*",
"extracted_events": [
{
"introduced": "0"
},
{
"fixed": "3.3.0"
}
]
}{
"source": "CPE_RANGE",
"cpe": "cpe:2.3:a:amazon:opensearch:*:*:*:*:*:*:*:*",
"extracted_events": [
{
"introduced": "0"
},
{
"fixed": "3.3.0"
}
]
}[
{
"digest": {
"threshold": 0.9,
"line_hashes": [
"337587567066112158846751319490848932766",
"243173086043611887157670314068874849103",
"106225951026862911709734728195754054001",
"156685412093741342926124056873922866848"
]
},
"deprecated": false,
"source": "https://github.com/opensearch-project/security/commit/53429a5853085da5258add822f768d248f70e228",
"signature_type": "Line",
"target": {
"file": "src/test/java/org/opensearch/security/UtilTests.java"
},
"signature_version": "v1",
"id": "CVE-2025-9624-08a72808"
},
{
"digest": {
"length": 705.0,
"function_hash": "322200501526791948964997181698709585593"
},
"deprecated": false,
"source": "https://github.com/opensearch-project/security/commit/53429a5853085da5258add822f768d248f70e228",
"signature_type": "Function",
"target": {
"file": "src/main/java/org/opensearch/security/support/WildcardMatcher.java",
"function": "from"
},
"signature_version": "v1",
"id": "CVE-2025-9624-4bb4be62"
},
{
"digest": {
"length": 1306.0,
"function_hash": "1626779747580519513273760754940738546"
},
"deprecated": false,
"source": "https://github.com/opensearch-project/security/commit/53429a5853085da5258add822f768d248f70e228",
"signature_type": "Function",
"target": {
"file": "src/test/java/org/opensearch/security/UtilTests.java",
"function": "testWildcardMatcherClasses"
},
"signature_version": "v1",
"id": "CVE-2025-9624-81dccea6"
},
{
"digest": {
"threshold": 0.9,
"line_hashes": [
"49348481963301136246504611664912369213",
"120217354522916930801294791257273832661",
"270107619082542973782573518277226409638",
"226764507510670630840363062915672452737"
]
},
"deprecated": false,
"source": "https://github.com/opensearch-project/security/commit/53429a5853085da5258add822f768d248f70e228",
"signature_type": "Line",
"target": {
"file": "src/main/java/org/opensearch/security/support/WildcardMatcher.java"
},
"signature_version": "v1",
"id": "CVE-2025-9624-ddfc0d62"
}
]
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-9624.json"
"2026-07-21T23:25:23Z"