CVE-2026-75897 - Uncontrolled ... Note

CVE-2026-75897 - Uncontrolled resource consumption in OpenSearch Dashboards capabilities route

Amazon OpenSearch Service has issued an important bulletin regarding a security vulnerability. The vulnerability, identified as CVE-2026-75897, affects OpenSearch Dashboards, the user interface for OpenSearch. This issue stems from improper input validation within the capabilities route handler. Specifically, the handler does not limit the size of the request payload. Remote attackers could exploit this by sending a crafted HTTP request. Such an exploit could lead to a denial of service, making the service unavailable. For self-managed OpenSearch, versions 1.3.0 through 3.7.0 inclusive are affected, along with 2.x releases up to 2.19.6. This vulnerability is inherited from upstream Kibana versions 7.7.1 through 7.10.2. Amazon OpenSearch Service versions 1.3, 2.11, 2.13, 2.15, 2.17, 2.19, 3.1, 3.3, and 3.5 are impacted, as are Elasticsearch compatibility versions using Kibana 7.9 and 7.10. AWS has released patched service software that is available for all affected Amazon OpenSearch Service versions, and users are advised to apply the latest service software update.