{"id":"CVE-2025-9624","aliases":["GHSA-mw3v-mmfw-3x2g"],"url":"https://o3.security/vulnerability/CVE-2025-9624","summary":"OpenSearch 3.2.0 - Nested Boolean/Disjunction asymmetric DoS","details":"A vulnerability in OpenSearch allows attackers to cause Denial of Service (DoS) by submitting complex query_string inputs.\n\n\n\nThis issue affects all OpenSearch versions between 3.0.0 and < 3.3.0 and OpenSearch < 2.19.4.","published":"2025-11-25T19:43:40.330Z","modified":"2026-08-12T15:32:41.141541Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Maven","name":"org.opensearch:opensearch-common","fixedVersion":"3.3.0"},{"ecosystem":"Maven","name":"org.opensearch:opensearch-common","fixedVersion":"2.19.4"}],"fix":{"url":"https://github.com/opensearch-project/OpenSearch/pull/19491","label":"opensearch-project/OpenSearch#19491"},"references":[{"type":"ADVISORY","url":"https://fluidattacks.com/advisories/chick"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/9xxx/CVE-2025-9624.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-9624"},{"type":"FIX","url":"https://github.com/opensearch-project/OpenSearch/releases/tag/2.19.4"},{"type":"FIX","url":"https://github.com/opensearch-project/OpenSearch/releases/tag/3.3.0"},{"type":"WEB","url":"https://github.com/opensearch-project/OpenSearch/pull/19491"},{"type":"WEB","url":"https://caverav.cl/posts/opensearch-dos/opensearch-dos"},{"type":"PACKAGE","url":"https://github.com/opensearch-project/OpenSearch"},{"type":"WEB","url":"https://opensearch.org/blog/explore-opensearch-3-3"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T15:32:41.141541Z"}}