A vulnerability has been found in AWS OpenSearch up to 3.4.x and classified as problematic. This vulnerability affects unknown code of the component Threat Intelligence Feed Parser. This manipulation causes server-side request forgery.

This vulnerability is handled as CVE-2026-18952. The attack can be initiated remotely. There is not any exploit available.

The affected component should be upgraded.