Package
opensearch-fips-3-security-analytics
Component
netty-handler
Latest update
8.1
CVSS V3
Build, ship, and run secure software with minimal, hardened container images — rebuilt from source daily and guarded under our industry-leading remediation SLA.
Start for freeStatus
Impact
The vulnerable netty component is bundled transitively in the plugin at a version pinned by the upstream OpenSearch platform build, which overrides dependency-level version forcing. The patched netty (4.1.135.Final) cannot be applied to the plugin distribution without an upstream change to the platform's netty version alignment; remediation awaits an upstream release that ships the fixed netty.
Status