VendorsOpenMetadataopenmetadataany version
Vulnerabilities

OpenMetadata Openmetadata any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

12CVEs
CVE-2024-28255
Authentication Bypass in OpenMetadata
Published 2024-03-15 · Analyzed
9.8EPSS 0.733
CVE-2024-28253
SpEL Injection in `PUT /api/v1/policies` in OpenMetadata
Published 2024-03-15 · Analyzed
9.4EPSS 0.125
CVE-2024-28254
SpEL Injection in `GET /api/v1/events/subscriptions/validation/condition/<expr>` in OpenMetadata
Published 2024-03-15 · Analyzed
8.8EPSS 0.457
CVE-2024-28848
SpEL Injection in `GET /api/v1/policies/validation/condition/<expr>` in OpenMetadata
Published 2024-03-15 · Analyzed
8.8EPSS 0.079
CVE-2024-28847
SpEL Injection in `PUT /api/v1/events/subscriptions` in OpenMetadata
Published 2024-03-15 · Analyzed
8.8EPSS 0.024
CVE-2024-55238
OpenMetadata <=1.4.1 is vulnerable to SQL Injection. An attacker can extract information from the database in function listCount in the WorkflowDAO interface. The workflowtype and status parameters can be used to build a SQL query.
Published 2025-04-17 · Analyzed
8.8EPSS 0.006
CVE-2025-50465
OpenMetadata <=1.4.4 is vulnerable to SQL Injection. An attacker can extract information from the database in function listCount in the TestDefinitionDAO interface. The testPlatform parameter can be used to build a SQL query.
Published 2025-08-08 · Analyzed
8.8EPSS 0.003
CVE-2026-22244
OpenMetadata Server-Side Template Injection (SSTI) in FreeMarker email templates that leads to RCE
Published 2026-01-08 · Modified
8.5EPSS 0.013
CVE-2026-26010
Leaky JWTs in OpenMetadata exposing highly-privileged bot users
Published 2026-02-11 · Analyzed
7.6EPSS 0.004
CVE-2025-50466
OpenMetadata <=1.4.4 is vulnerable to SQL Injection. An attacker can extract information from the database in function listCount in the TestDefinitionDAO interface. The entityType parameter can be used to build a SQL query.
Published 2025-08-08 · Analyzed
7.1EPSS 0.003
CVE-2025-50468
OpenMetadata <=1.4.4 is vulnerable to SQL Injection. An attacker can extract information from the database in function listCount in the DocStoreDAO interface. The entityType parameters can be used to build a SQL query.
Published 2025-08-08 · Analyzed
6.5EPSS 0.003
CVE-2025-50467
OpenMetadata <=1.4.4 is vulnerable to SQL Injection. An attacker can extract information from the database in function listCount in the TestDefinitionDAO interface. The supportedDataTypeParam parameter can be used to build a SQL query.
Published 2025-08-08 · Analyzed
6.5EPSS 0.003