/
DirectorySecurity AdvisoriesPricing
Sign in
Security Advisories

CGA-9rc9-5wg2-7836

Published

Last updated

https://images.chainguard.dev/security/CGA-9rc9-5wg2-7836
Package

opensearch-2

Repository

Chainguard

Latest Update
Pending upstream fix
Aliases
  • CVE-2025-22227
  • GHSA-4q2v-9p7v-3v22

Severity

Unknown

References

  • https://nvd.nist.gov/vuln/detail/CVE-2025-22227

Updates

Status

Pending upstream fix

Impact

The reactor-netty-http @ 1.1.23 vulnerability cannot be fixed in OpenSearch 2.19.1 due to complex functional changes required for the security update. OpenSearch upstream attempted a backport to the 2.x branch but it failed. OpenSearch 3.x is slated to include reactor-netty 1.2.5+ which contains the precursors for the fix. References: Failed backport: https://github.com/opensearch-project/OpenSearch/pull/17377#issuecomment-2777169427, https://github.com/opensearch-project/OpenSearch/commit/eb905709242eff2f95807f74981590251dad85e7, https://github.com/opensearch-project/OpenSearch/commit/c060f92b6d5ee4fb6f6c92aa1912d34e6d5dfe91, https://github.com/opensearch-project/OpenSearch/commit/fa4595cf853f2f55b6a4ffc9f653330f6a25688d

Status

Under investigation

Status

Fixed

Fixed version

2.19.1-r6

Status

Under investigation


Safe Source for Open Sourceâ„¢
Contact us
© 2025 Chainguard. All Rights Reserved.
Private PolicyTerms of Use

Product

Chainguard ContainersChainguard LibrariesChainguard VMsIntegrationsPricing