CVE-2025-9624: OpenSearch 3.2.0 - Nested Boolean/Disjunction asymmetric DoS
A vulnerability in OpenSearch allows attackers to cause Denial of Service (DoS) by submitting complex querystring inputs.
This issue affects all OpenSearch versions below 3.2.0.
Other sources
A vulnerability in OpenSearch allows attackers to cause Denial of Service (DoS) by submitting complex querystring inputs.
This issue affects all OpenSearch versions between 3.0.0 and < 3.3.0 and OpenSearch < 2.19.4.
— MITRE
A vulnerability in OpenSearch allows attackers to cause Denial of Service (DoS) by submitting complex querystring inputs.
This issue affects all OpenSearch versions below 2.19.4 and versions 3.0.0 through 3.2.0.
— GitHub
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-9624?
CVE-2025-9624 has been assessed to have a high severity due to its potential to cause Denial of Service.
How do I fix CVE-2025-9624?
To fix CVE-2025-9624, upgrade OpenSearch to version 3.2.0 or higher.
What is the impact of CVE-2025-9624?
CVE-2025-9624 allows attackers to disrupt service by submitting complex query_string inputs.
Is CVE-2025-9624 present in all OpenSearch versions?
CVE-2025-9624 affects all OpenSearch versions prior to 3.2.0.
How can I determine if I am vulnerable to CVE-2025-9624?
You are vulnerable to CVE-2025-9624 if you are using an OpenSearch version below 3.2.0.