Skip to main content

Vendor/product archive

open-metadata / openmetadata CVEs

Beta · best-effort

12 CVEs tagged to open-metadata / openmetadata2 Critical, 8 High, 2 Medium, 0 Low, 0 Unrated.

CVE-2026-26010

Published Feb 11, 2026

OpenMetadata is a unified metadata platform. Prior to 1.11.8, calls issued by the UI against /api/v1/ingestionPipelines leak JWTs used by ingestion-bot for certain services (Glue…

CVSS 7.6 · High
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2026-22244

Published Jan 8, 2026

OpenMetadata is a unified metadata platform. Versions prior to 1.11.4 are vulnerable to remote code execution via Server-Side Template Injection (SSTI) in FreeMarker email templat…

CVSS 8.5 · High
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2025-50468

Published Aug 8, 2025

OpenMetadata <=1.4.4 is vulnerable to SQL Injection. An attacker can extract information from the database in function listCount in the DocStoreDAO interface. The entityType param…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-50467

Published Aug 8, 2025

OpenMetadata <=1.4.4 is vulnerable to SQL Injection. An attacker can extract information from the database in function listCount in the TestDefinitionDAO interface. The supportedD…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-50466

Published Aug 8, 2025

OpenMetadata <=1.4.4 is vulnerable to SQL Injection. An attacker can extract information from the database in function listCount in the TestDefinitionDAO interface. The entityType…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2025-50465

Published Aug 8, 2025

OpenMetadata <=1.4.4 is vulnerable to SQL Injection. An attacker can extract information from the database in function listCount in the TestDefinitionDAO interface. The testPlatfo…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2024-55238

Published Apr 17, 2025

OpenMetadata <=1.4.1 is vulnerable to SQL Injection. An attacker can extract information from the database in function listCount in the WorkflowDAO interface. The workflowtype and…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2024-28848

Published Mar 15, 2024

OpenMetadata is a unified platform for discovery, observability, and governance powered by a central metadata repository, in-depth lineage, and seamless team collaboration. The `‎…

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2024-28847

Published Mar 15, 2024

OpenMetadata is a unified platform for discovery, observability, and governance powered by a central metadata repository, in-depth lineage, and seamless team collaboration. Simila…

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2024-28255

Published Mar 15, 2024

OpenMetadata is a unified platform for discovery, observability, and governance powered by a central metadata repository, in-depth lineage, and seamless team collaboration. The `J…

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2024-28254

Published Mar 15, 2024

OpenMetadata is a unified platform for discovery, observability, and governance powered by a central metadata repository, in-depth lineage, and seamless team collaboration. The `‎…

CVSS 8.8 · High
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2024-28253

Published Mar 15, 2024

OpenMetadata is a unified platform for discovery, observability, and governance powered by a central metadata repository, in-depth lineage, and seamless team collaboration. `Compi…

CVSS 9.4 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort
Showing 1-12 of 12 CVEsPage 1 of 1