CVE-2026-75897: Aws Amazon Opensearch Service

High severity, CVSS 7.5. EPSS: 0.7% chance of exploitation in the next 30 days.

Improper input validation in the capabilities route handler in OpenSearch Dashboards - the size of the request payload is not bounded - might allow remote attackers to cause a denial of service via a crafted HTTP request.

Affected products

  • Aws Amazon Opensearch Service: from 1.3, up to and including 3.5
  • Opensearch Opensearch Dashboards: from 1.3, up to and including 3.7.0

Published 2026-08-18. Last modified 2026-08-20.