VYPR

OpenSearch SQL plugin

by Opensearch Project

CVEs (1)

  • CVE-2026-83497HigAug 31, 2026
    risk 0.57cvss 8.8epss

    Unrestricted deserialization of untrusted data in the cursor pagination component in the OpenSearch SQL plugin allows a remote authenticated user with basic read/search permissions to execute arbitrary code on the server by sending a crafted cursor parameter to the plugins/sql…