If you discover a potential security issue in this project we ask that you notify OpenSearch Security directly via email to security@opensearch.org. Please do not create a public GitHub issue.
Security: opensearch-project/sql
Security
SECURITY.md
-
SQL Query Validation Bypass in OpenSearch Direct QueryGHSA-g4jr-343c-fvjm published
Aug 10, 2026 by cwperksHigh -
Unsafe deserialization of untrusted data in SQL plugin cursor parameterGHSA-r8cv-xvqm-4qj4 published
Jun 30, 2026 by cwperksHigh
Learn more about advisories related to opensearch-project/sql in the GitHub Advisory Database