OpenMetadata vulnerabilities
CVEs whose affected-version data names the OpenMetadata package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
2 CVEsRSS
CVE-2026-100373Medium· 4.1PoCOpenMetadata through 2.0.2 contains a server-side request forgery vulnerability in the URLValidator.validateURL function that fails to properly resolve DNS hostnames and validate internal addresses
OpenMetadata through 2.0.2 contains a server-side request forgery vulnerability in the URLValidator.validateURL function that fails to properly resolve DNS hostnames and validate internal addresses. Users permitted to create or update Ev…
▾ Twilightopen-metadata · OpenMetadatavia NVD
CVE-2026-22244High· 7.2OpenMetadata is a unified metadata platform
OpenMetadata is a unified metadata platform. Versions 1.5.0 through 1.11.3 are vulnerable to remote code execution via Server-Side Template Injection (SSTI) in FreeMarker email templates. An attacker must have administrative privileges t…
▾ Twilightopen-metadata · openmetadataEPSS 1.3%via NVD