PT-2026-41509 · Redsoft+1 · Opensearch+9
Published
2026-05-07
·
Updated
2026-05-29
CVSS v3.1
2.2
Low
| Vector | AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
OpenSearch versions 2.18.0 through 2.19.3
OpenSearch versions 3.0.0 through 3.2.x
Description
A regression caused the
plugins.security.ssl.transport.enforce hostname verification setting to be ineffective. When enabled, the system failed to verify that the hostname in a connecting node's TLS certificate matched the connection hostname. This allows a node with a valid certificate signed by the cluster's trusted CA to join the cluster even if the Subject Alternative Name (SAN) is incorrect. This issue affects the hostname verification check but does not impact general certificate validation.Recommendations
Update to version 2.19.4.
Update to version 3.3.0.
Use more restrictive values for
plugins.security.nodes dn to limit which certificates are accepted for node-to-node communication.Fix
Improper Certificate Validation
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Opensearch
Opensearch-Ingest-Attachment-Plugin
Opensearch-Mapper-Annotated-Text-Plugin
Opensearch-Mapper-Murmur3-Plugin
Opensearch-Mapper-Size-Plugin
Opensearch-Repository-Hdfs-Plugin
Opensearch-Repository-S3-Plugin
Opensearch-Store-Mb-Plugin
Opensearch-Transport-Nio-Plugin
Org.Opensearch.Plugin:Opensearch-Security