CVE-2026-75897 - Uncontrolled resource consumption in OpenSearch Dashboards capabilities route
Opensearch Dashboards ยท 2026-08-20
Actions
Technical Details
| Affected Versions | 1.3.0 through 3.7.0, OpenSearch 1.3, 2.11, 2.13, 2.15, 2.17, 2.19, 3.1, 3.3, 3.5 |
|---|---|
| Regions | all |
| CVE IDs | CVE-2026-75897 |
| Migration Required | Yes |
| Cost Impact | Neutral |
| IaC Impact | High |
What This Means
For DevOps Teams
Update OpenSearch Dashboards to version 3.8.0 or later, and apply the latest service software update for Amazon OpenSearch Service to address the security vulnerability.
For Platform Teams
Deploy the patched versions of OpenSearch Dashboards and Amazon OpenSearch Service to maintain system security and stability.
For Executives
Implement the security patch for OpenSearch Dashboards to mitigate risk of denial of service attacks and ensure system stability.
Source
Related Opensearch Dashboards Updates
- ARC Region switch adds Amazon RDS Switchover Read Replica execution blockย (2026-08-20)
- PostgreSQL 19 Beta 3 is now available in Amazon RDS Database Preview Environment (2026-08-18)
- Amazon RDS for Oracle now supports Oracle Application Express (APEX) version 26.1 (2026-08-14)
- Amazon RDS for MariaDB now supports MariaDB 12.3 (2026-08-11)
- Amazon RDS now provides visibility into storage volume initialization status (2026-08-06)