-
CVSS Score
-Basic Information
CVE ID
-
GHSA ID
-
EPSS Score
-
CWE
-
Published
-
Updated
-
KEV Status
-
Technology
-
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| org.opensearch:opensearch | maven | < 1.3.14 | 1.3.14 |
| org.opensearch:opensearch | maven | >= 2.0.0, < 2.11.1 | 2.11.1 |
The vulnerability manifests in the _search API's query parsing logic. Stack overflow vulnerabilities in query processing typically occur in recursive parsing functions without depth limits. QueryStringQueryBuilder.fromXContent is the primary entry point for parsing query strings in OpenSearch, and similar vulnerabilities in Elasticsearch (referenced via ESA-2023-14) have historically been found in equivalent query parsing functions. The fixed versions likely added recursion depth checks in this parsing path.
Ongoing coverage of React2Shell