Skip to content

Resolved CVE-2026-27903, CVE-2026-27904, CVE-2026-33671, CVE-2026-33750, and CVE-2026-33532.#1436

Merged
AWSHurneyt merged 2 commits into
opensearch-project:2.5from
AWSHurneyt:fix/cve-resolutions-2.5
May 19, 2026
Merged

Resolved CVE-2026-27903, CVE-2026-27904, CVE-2026-33671, CVE-2026-33750, and CVE-2026-33532.#1436
AWSHurneyt merged 2 commits into
opensearch-project:2.5from
AWSHurneyt:fix/cve-resolutions-2.5

Conversation

@AWSHurneyt
Copy link
Copy Markdown
Collaborator

Summary

Resolves the following CVEs by adding yarn resolutions:

Testing

  • yarn build passes

…, and CVE-2026-33532.

Signed-off-by: Thomas Hurney <hurneyt@amazon.com>
@AWSHurneyt AWSHurneyt force-pushed the fix/cve-resolutions-2.5 branch from 08cd2ea to 5a663b6 Compare May 12, 2026 20:31
@AWSHurneyt
Copy link
Copy Markdown
Collaborator Author

The unit test workflows are failing because of the brace-expansion@5.0.5 bump. This was needed to address CVE-2026-33750. That version is incompatible with node versions under Node 18; however, OpenSearch-Dashboards currently uses Node 16 for version branches 2.0-2.9. If another patch is released for those older versions, OSD will need to bump the version of node for compatibility.

Signed-off-by: Thomas Hurney <hurneyt@amazon.com>
@AWSHurneyt AWSHurneyt closed this May 14, 2026
@AWSHurneyt AWSHurneyt reopened this May 14, 2026
@AWSHurneyt AWSHurneyt merged commit 12c4c12 into opensearch-project:2.5 May 19, 2026
4 of 9 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants