| opensearch-2 | 2.19.1-r2 | CRITICAL | CVE-2025-54988 | 2.19.4-r0 | |
| opensearch-2 | 2.19.1-r2 | HIGH | CVE-2025-27817 | 2.19.1-r5 | |
| opensearch-2 | 2.19.1-r2 | HIGH | CVE-2025-27820 | 2.19.4-r0 | |
| opensearch-2 | 2.19.1-r2 | HIGH | CVE-2025-55163 | 2.19.4-r0 | |
| opensearch-2 | 2.19.1-r2 | HIGH | CVE-2025-48734 | 2.19.4-r0 | |
| opensearch-2 | 2.19.1-r2 | HIGH | CVE-2025-58057 | 2.19.4-r0 | |
| opensearch-common | 2.19.1 | HIGH | GHSA-mw3v-mmfw-3x2g | 2.19.4 | OpenSearch is vulnerable to DoS via complex query_string inputs |
| opensearch-2 | 2.19.1-r2 | HIGH | CVE-2025-9624 | 2.19.4-r0 | |
| opensearch-2 | 2.19.1-r2 | HIGH | CVE-2025-58056 | 2.19.4-r0 | |
| opensearch-2 | 2.19.1-r2 | HIGH | CVE-2024-57699 | 2.19.4-r0 | |
| jackson-core | 2.18.2 | HIGH | GHSA-72hv-8253-57qq | 2.18.6 | jackson-core: Number Length Constraint Bypass in Async Parser Leads to Potential DoS Condition |
| jackson-core | 2.18.2 | HIGH | GHSA-72hv-8253-57qq | 2.18.6 | jackson-core: Number Length Constraint Bypass in Async Parser Leads to Potential DoS Condition |
| log4j-core | 2.21.0 | MEDIUM | GHSA-vc5p-v9hr-52mj | 2.25.3 | Apache Log4j does not verify the TLS hostname in its Socket Appender |
| bc-fips | 2.0.0 | MEDIUM | GHSA-67mf-3cr5-8w23 | 2.0.1 | Bouncy Castle for Java on All (API modules) allows Excessive Allocation |
| netty-codec | 4.1.118.Final | MEDIUM | GHSA-3p8m-j85q-pgmj | 4.1.125.Final | Netty's decoders vulnerable to DoS via zip bomb style attack |
| opensearch-2 | 2.19.1-r2 | MEDIUM | CVE-2025-8916 | 2.19.4-r0 | |
| netty-codec-http | 4.1.118.Final | MEDIUM | GHSA-84h7-rjj3-6jx4 | 4.1.129.Final | Netty has a CRLF Injection vulnerability in io.netty.handler.codec.http.HttpRequestEncoder |
| opensearch-2 | 2.19.1-r2 | MEDIUM | CVE-2025-67735 | 2.19.4-r6 | |
| opensearch-2 | 2.19.1-r2 | MEDIUM | CVE-2025-48924 | 2.19.4-r0 | |
| netty-codec-http | 4.1.118.Final | LOW | GHSA-fghv-69vj-qj49 | 4.1.125.Final | Netty vulnerable to request smuggling due to incorrect parsing of chunk extensions |
| opensearch-2 | 2.19.1-r2 | UNKNOWN | GHSA-3p8m-j85q-pgmj | 2.19.4-r0 | |
| opensearch-2 | 2.19.1-r2 | UNKNOWN | GHSA-4cx2-fc23-5wg6 | 2.19.4-r0 | |
| opensearch-2 | 2.19.1-r2 | UNKNOWN | GHSA-73m2-qfq3-56cx | 2.19.4-r0 | |
| opensearch-2 | 2.19.1-r2 | UNKNOWN | GHSA-84h7-rjj3-6jx4 | 2.19.4-r6 | |
| opensearch-2 | 2.19.1-r2 | UNKNOWN | GHSA-fghv-69vj-qj49 | 2.19.4-r0 | |
| opensearch-2 | 2.19.1-r2 | UNKNOWN | GHSA-j288-q9x7-2f5v | 2.19.4-r0 | |
| opensearch-2 | 2.19.1-r2 | UNKNOWN | GHSA-mw3v-mmfw-3x2g | 2.19.4-r0 | |
| opensearch-2 | 2.19.1-r2 | UNKNOWN | GHSA-p72g-pv48-7w9x | 2.19.4-r0 | |
| opensearch-2 | 2.19.1-r2 | UNKNOWN | GHSA-pq2g-wx69-c263 | 2.19.4-r0 | |
| opensearch-2 | 2.19.1-r2 | UNKNOWN | GHSA-prj3-ccx8-p6x4 | 2.19.4-r0 | |
| opensearch-2 | 2.19.1-r2 | UNKNOWN | GHSA-vgq5-3255-v292 | 2.19.1-r5 | |
| opensearch-2 | 2.19.1-r2 | UNKNOWN | GHSA-wxr5-93ph-8wr9 | 2.19.4-r0 | |