Skip to content

Resolved CVE-2026-27903, CVE-2026-27904, CVE-2026-33671, CVE-2026-33750, and CVE-2026-33532.#1432

Merged
AWSHurneyt merged 2 commits into
opensearch-project:2.9from
AWSHurneyt:fix/cve-resolutions-2.9
May 19, 2026
Merged

Resolved CVE-2026-27903, CVE-2026-27904, CVE-2026-33671, CVE-2026-33750, and CVE-2026-33532.#1432
AWSHurneyt merged 2 commits into
opensearch-project:2.9from
AWSHurneyt:fix/cve-resolutions-2.9

Conversation

@AWSHurneyt
Copy link
Copy Markdown
Collaborator

Summary

Resolves the following CVEs by adding yarn resolutions:

Testing

  • yarn build passes

…, and CVE-2026-33532.

Signed-off-by: Thomas Hurney <hurneyt@amazon.com>
@AWSHurneyt AWSHurneyt force-pushed the fix/cve-resolutions-2.9 branch from 0adc250 to 0d4d7f6 Compare May 12, 2026 20:31
@AWSHurneyt
Copy link
Copy Markdown
Collaborator Author

The unit test workflows are failing because of the brace-expansion@5.0.5 bump. This was needed to address CVE-2026-33750. That version is incompatible with node versions under Node 18; however, OpenSearch-Dashboards currently uses Node 16 for version branches 2.0-2.9. If another patch is released for those older versions, OSD will need to bump the version of node for compatibility.

Signed-off-by: Thomas Hurney <hurneyt@amazon.com>
@AWSHurneyt AWSHurneyt closed this May 14, 2026
@AWSHurneyt AWSHurneyt reopened this May 14, 2026
@AWSHurneyt AWSHurneyt merged commit be843e5 into opensearch-project:2.9 May 19, 2026
4 of 9 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants