CVE-2026-75897
Improper input validation in the capabilities route handler in OpenSearch Dashboards - the size of the request payload is not bounded - might allow remote attackers to cause a denial of service via a crafted HTTP request.
- Published Aug 18, 2026
- CVSS 8.7 high
- 0.7% chance of exploitation in the next 30 days (EPSS)
Affected software
In the news
- CVE-2026-75897 - Uncontrolled resource consumption in OpenSearch Dashboards capabilities route AWS Security Bulletins ·