7.5
CVSS CVSS_V3
Status
Impact
The netty-codec-http vulnerability is a transitive dependency brought in through dependencies in OpenSearch's submodules. Bumping to the fix version of netty causes build failures. Upstream maintainers will need to implement compatibility into the affected submodules.
Status