Next.js zero-day vulnerabilities in opensearch 2.16+

Hi Team!

We are upgrading from Elasticsearch 7.0.1 to OpenSearch 2.16. During security tests, we were notified that the Next.js embedded with Kibana (7.0.1) had zero-day vulnerabilities affecting Next.js [1].

As we prepare to upgrade to OpenSearch, could you confirm whether the Next.js vulnerability is still present in version 2.16+?

[1] CVE-2025-29927 | Next.js

Hi Team,

Please help us by responding the above.

Regards,

Erik