CVE-2026-18952

Summary

Missing input validation in the threat intelligence feed parser in the OpenSearch Security Analytics plugin might allow an authenticated remote user to perform server-side request forgery and read local files via a crafted URL parameter to the threat intel source configuration endpoint.

Affected Software

VendorProductVersion RangeStatus
AWSOpensearch2.15.0 < 3.5.0affected
GithubOpensearch2.15.0 < 3.5.0affected

Weaknesses

  • CWE-918: CWE-918 Server-Side request forgery (SSRF)

References