Impact
Improper validation of the request body in the capabilities route of OpenSearch Dashboards allows an attacker to send a payload of arbitrary size. The absence of a bounded request size can cause the server to consume excessive memory or CPU resources, potentially leading to memory exhaustion and denial of service. The weakness is classified as CWE‑1284, an uncontrolled resource consumption issue. This can degrade or completely disrupt the availability of dashboard services for affected users.
Affected Systems
The vulnerability affects Amazon OpenSearch Service and OpenSearch Dashboards. Precise version information is not provided; however, any instance exposing the capabilities route is potentially impacted. Both cloud‑managed and self‑hosted deployments of OpenSearch Dashboards are within scope.
Risk and Exploitability
The CVSS score of 8.7 indicates a high severity of this denial‑of‑service vulnerability. Although the EPSS score is unavailable, the lack of a KEV listing suggests no widespread public exploitation yet. Based on the description, a remote attacker can reach the affected endpoint over HTTP without any prerequisite authentication, making the exploit potentially trivially achievable by connecting to the dashboard’s network interface. The likelihood of exploitation is considered significant given the high CVSS and the nature of the weakness.
OpenCVE Enrichment