Open-metadata
Open-metadata Openmetadata: vulnerabilities and CVEs
Open-metadata Openmetadata has 15 published vulnerabilities, 5 of them in the last 12 months. 1 are rated critical and 0 are listed by CISA as actively exploited.
CVEs15
Last 12 months5
Critical1
Actively exploited0
All vulnerabilities in the catalogue →⭐ Follow this technology
Latest vulnerabilities
| CVE | Severity | EPSS | Active exploitation | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-100373 | Medium (5.1) | 0.26% | — | Sep 25, 2026 | OpenMetadata through 2.0.2 contains a server-side request forgery vulnerability in the URLValidator.validateURL function that fails to properly resolve DNS hostnames and validate internal addresses. Users permitted to… |
| CVE-2026-81029 | High (8.5) | 0.55% | — | Aug 26, 2026 | OpenMetadata accepts a caller-supplied post-authentication redirect target and appends the issued token to it. SamlLoginServlet reads the callback request parameter and stores it in the HTTP session without comparing it… |
| CVE-2026-46481 | High (8.3) | 0.42% | — | Jun 8, 2026 | OpenMetadata is a unified metadata platform. Prior to version 1.12.4, a non-admin SSO user can trigger a TEST_CONNECTION workflow for a Database Service and receive, in the HTTP 201 response of POST… |
| CVE-2026-26010 | High (7.6) | 0.36% | — | Feb 11, 2026 | OpenMetadata is a unified metadata platform. Prior to 1.11.8, calls issued by the UI against /api/v1/ingestionPipelines leak JWTs used by ingestion-bot for certain services (Glue / Redshift / Postgres). Any read-only… |
| CVE-2026-22244 | High (8.5) | 1.3% | — | Jan 8, 2026 | OpenMetadata is a unified metadata platform. Versions 1.5.0 through 1.11.3 are vulnerable to remote code execution via Server-Side Template Injection (SSTI) in FreeMarker email templates. An attacker must have… |
| CVE-2025-50468 | Medium (6.5) | 0.30% | — | Aug 8, 2025 | OpenMetadata <=1.4.4 is vulnerable to SQL Injection. An attacker can extract information from the database in function listCount in the DocStoreDAO interface. The entityType parameters can be used to build a SQL query. |
| CVE-2025-50467 | Medium (6.5) | 0.26% | — | Aug 8, 2025 | OpenMetadata <=1.4.4 is vulnerable to SQL Injection. An attacker can extract information from the database in function listCount in the TestDefinitionDAO interface. The supportedDataTypeParam parameter can be used to… |
| CVE-2025-50466 | Medium (6.5) | 0.33% | — | Aug 8, 2025 | OpenMetadata <=1.4.4 is vulnerable to SQL Injection. An attacker can extract information from the database in function listCount in the TestDefinitionDAO interface. The entityType parameter can be used to build a SQL… |
| CVE-2025-50465 | High (8.8) | 0.32% | — | Aug 8, 2025 | OpenMetadata <=1.4.4 is vulnerable to SQL Injection. An attacker can extract information from the database in function listCount in the TestDefinitionDAO interface. The testPlatform parameter can be used to build a SQL… |
| CVE-2024-55238 | High (8.8) | 0.61% | — | Apr 17, 2025 | OpenMetadata <=1.4.1 is vulnerable to SQL Injection. An attacker can extract information from the database in function listCount in the WorkflowDAO interface. The workflowtype and status parameters can be used to build… |
| CVE-2024-28848 | High (8.8) | 7.9% | — | Mar 15, 2024 | OpenMetadata is a unified platform for discovery, observability, and governance powered by a central metadata repository, in-depth lineage, and seamless team collaboration. The `CompiledRule::validateExpression` method… |
| CVE-2024-28847 | High (8.8) | 2.4% | — | Mar 15, 2024 | OpenMetadata is a unified platform for discovery, observability, and governance powered by a central metadata repository, in-depth lineage, and seamless team collaboration. Similarly to the GHSL-2023-250 issue,… |
| CVE-2024-28255 | Critical (9.8) | 73% | — | Mar 15, 2024 | OpenMetadata is a unified platform for discovery, observability, and governance powered by a central metadata repository, in-depth lineage, and seamless team collaboration. The `JwtFilter` handles the API authentication… |
| CVE-2024-28254 | High (8.8) | 46% | — | Mar 15, 2024 | OpenMetadata is a unified platform for discovery, observability, and governance powered by a central metadata repository, in-depth lineage, and seamless team collaboration. The `AlertUtil::validateExpression` method… |
| CVE-2024-28253 | High (8.8) | 13% | — | Mar 15, 2024 | OpenMetadata is a unified platform for discovery, observability, and governance powered by a central metadata repository, in-depth lineage, and seamless team collaboration. `CompiledRule::validateExpression` is also… |
🎯 How it gets exploited (ATT&CK techniques)
Number of CVEs of this technology mapped to each exploitation or primary-impact technique.