Home/Product/open metadata openmetadata
Product

open metadata openmetadata

12 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2026-26010
< 1.11.8
OpenMetadata is a unified metadata platform. Prior to 1.11.8, calls issued by the UI against /api/v1/ingestionPipelines leak JWTs
7.6HIGH
CVE-2026-22244
< 1.11.4
OpenMetadata is a unified metadata platform. Versions prior to 1.11.4 are vulnerable to remote code execution via Server-Side Temp
7.2HIGH
CVE-2025-50468
<= 1.4.4
OpenMetadata <=1.4.4 is vulnerable to SQL Injection. An attacker can extract information from the database in function listCount i
6.5MEDIUM
CVE-2025-50467
<= 1.4.4
OpenMetadata <=1.4.4 is vulnerable to SQL Injection. An attacker can extract information from the database in function listCount i
6.5MEDIUM
CVE-2025-50466
<= 1.4.4
OpenMetadata <=1.4.4 is vulnerable to SQL Injection. An attacker can extract information from the database in function listCount i
7.1HIGH
CVE-2025-50465
<= 1.4.4
OpenMetadata <=1.4.4 is vulnerable to SQL Injection. An attacker can extract information from the database in function listCount i
7.1HIGH
CVE-2024-55238
<= 1.4.1
OpenMetadata <=1.4.1 is vulnerable to SQL Injection. An attacker can extract information from the database in function listCount i
7.1HIGH
CVE-2024-28848
< 1.2.4
OpenMetadata is a unified platform for discovery, observability, and governance powered by a central metadata repository, in-depth
8.8HIGH
CVE-2024-28847
< 1.2.4
OpenMetadata is a unified platform for discovery, observability, and governance powered by a central metadata repository, in-depth
8.8HIGH
CVE-2024-28255
< 1.2.4
OpenMetadata is a unified platform for discovery, observability, and governance powered by a central metadata repository, in-depth
9.8CRITICAL
CVE-2024-28254
< 1.2.4
OpenMetadata is a unified platform for discovery, observability, and governance powered by a central metadata repository, in-depth
8.8HIGH
CVE-2024-28253
< 1.3.1
OpenMetadata is a unified platform for discovery, observability, and governance powered by a central metadata repository, in-depth
9.4CRITICAL
threatengine.sh