PT-2026-41509 · Redsoft+1 · Opensearch+9

Published

2026-05-07

·

Updated

2026-05-29

CVSS v3.1

2.2

Low

VectorAV:N/AC:H/PR:H/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions OpenSearch versions 2.18.0 through 2.19.3 OpenSearch versions 3.0.0 through 3.2.x
Description A regression caused the plugins.security.ssl.transport.enforce hostname verification setting to be ineffective. When enabled, the system failed to verify that the hostname in a connecting node's TLS certificate matched the connection hostname. This allows a node with a valid certificate signed by the cluster's trusted CA to join the cluster even if the Subject Alternative Name (SAN) is incorrect. This issue affects the hostname verification check but does not impact general certificate validation.
Recommendations Update to version 2.19.4. Update to version 3.3.0. Use more restrictive values for plugins.security.nodes dn to limit which certificates are accepted for node-to-node communication.

Fix

Improper Certificate Validation

Weakness Enumeration

Related Identifiers

GHSA-X5HG-X4GV-J98M

Affected Products

Opensearch
Opensearch-Ingest-Attachment-Plugin
Opensearch-Mapper-Annotated-Text-Plugin
Opensearch-Mapper-Murmur3-Plugin
Opensearch-Mapper-Size-Plugin
Opensearch-Repository-Hdfs-Plugin
Opensearch-Repository-S3-Plugin
Opensearch-Store-Mb-Plugin
Opensearch-Transport-Nio-Plugin
Org.Opensearch.Plugin:Opensearch-Security