CVE-2026-75897: Uncontrolled Resource Consumption in Capabilities Route in OpenSearch Dashboards
Improper input validation in the capabilities route handler in OpenSearch Dashboards - the size of the request payload is not bounded - might allow remote attackers to cause a denial of service via a crafted HTTP request.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
Any deployment where the capabilities route is reachable over the network may be exposed, because exploitation is described as possible through a crafted HTTP request and requires no privileges or user interaction.
What does an attacker need to do?
An attacker needs only to send a crafted HTTP request with an unbounded payload to the capabilities route. The reported impact is denial of service; no confidentiality or integrity impact is stated.
What should I do if I cannot immediately determine whether my deployment is affected?
The provided information does not identify affected or fixed versions, configuration prerequisites, or temporary mitigations. Review the vendor security bulletin and OpenSearch downloads reference for available updates and guidance.