← All images

opensearch

18 open findings · 21 with upstream fix available

Image: ghcr.io/rtvkiz/minimal-opensearch:latest  ·  Size: 596 MB  ·  Last rebuilt: 0d ago  ·  Updated: 2026-06-17 21:45 UTC

PackageVersionSeverityCVEFixDescriptionVEX
opensearch-33.6.0-r5CRITICALCVE-2026-476913.6.0-r7
opensearch-33.6.0-r5CRITICALCVE-2026-456743.6.0-r7
netty-handler4.2.13.FinalHIGHGHSA-x4gw-5cx5-pgmh4.2.15.FinalNetty: SNI handler pre-allocates up to 16 MiB from nine attacker bytes
netty-handler4.2.13.FinalHIGHGHSA-3qp7-7mw8-wx864.2.15.FinalNetty has an IPv6 Subnet Filter Bypass via Incorrect Comparator Masking
netty-codec-http34.2.13.FinalHIGHGHSA-4grm-h2qv-h6w64.2.15.FinalNetty HTTP/3 QPACK Blocked Streams Memory Exhaustion
netty-codec-http34.2.13.FinalHIGHGHSA-c2rx-5r8w-8xr24.2.15.FinalNetty has a Vulnerable Default Configuration Which Leads to Denial of Service via Unbounded HTTP/3 Header Size
opensearch-33.6.0-r5HIGHCVE-2026-448923.6.0-r7
netty-codec-classes-quic4.2.13.FinalHIGHGHSA-cmm3-54f8-px4j4.2.15.FinalNetty's Default QUIC token handler accepts any client-supplied token
opensearch-33.6.0-r5HIGHCVE-2026-448943.6.0-r7
netty-handler4.2.13.FinalHIGHGHSA-c653-97m9-rcg94.2.15.FinalNetty: Wrapping plain trust manager silently disables hostname verification
netty-codec-http24.2.13.FinalMEDIUMGHSA-c2gf-v879-257j4.2.15.Finalnetty-codec-http2: ByteBuf Reference-Count Leak in DelegatingDecompressorFrameListener Leads to Memory Exhaustion
netty-codec-http24.2.13.FinalMEDIUMGHSA-5x3r-wrvg-rp6q4.2.15.FinalNetty HTTP/2: Advertised MAX_CONCURRENT_STREAMS are not enforced
opensearch-33.6.0-r5MEDIUMCVE-2026-456733.6.0-r7
netty-codec-http24.2.13.FinalMEDIUMGHSA-563q-j3cm-6jxm4.2.15.FinalNetty susceptible to HTTP/2 Reset Attack with different on-the-wire signature
netty-codec-http4.2.13.FinalMEDIUMGHSA-hvcg-qmg6-jm4c4.2.15.FinalNetty: HttpObjectDecoder skips arbitrary initial control characters when only initial CRLF characters are permitted
netty-codec-classes-quic4.2.13.FinalMEDIUMGHSA-cq4q-cv5g-r8q54.2.15.FinalNetty: QUIC stateless reset token material exposed through header-visible connection IDs
bc-fips2.1.2MEDIUMGHSA-mx76-r943-rf8gBouncy Castle has a vulnerability in program files gcm128w, gcm512w
bc-fips2.1.2MEDIUMGHSA-mx76-r943-rf8gBouncy Castle has a vulnerability in program files gcm128w, gcm512w
opensearch-33.6.0-r5UNKNOWNGHSA-5pvg-856g-cp853.6.0-r7
opensearch-33.6.0-r5UNKNOWNGHSA-676x-f7gg-47vc3.6.0-r7
opensearch-33.6.0-r5UNKNOWNGHSA-c2rx-5r8w-8xr23.6.0-r7
opensearch-33.6.0-r5UNKNOWNGHSA-cmm3-54f8-px4j3.6.0-r7
opensearch-33.6.0-r5UNKNOWNGHSA-xmv7-r254-6q783.6.0-r7