Open Metadata maintains a metadata management and governance platform that, despite a narrow product scope, has achieved prominence among data engineering and catalog platforms. The vendor's vulnerability disclosures reflect the complexity of its data-integration and API-driven architecture, though specific recurring weakness patterns have not yet emerged as a defining structural signal. Current exploitation activity, severity distribution, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Open Metadata over time
Signals from CVEs in this vendor scope (12 CVEs).
12 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-28255CRITICAL OpenMetadata is a unified platform for discovery, observability, and governance powered by a central metadata repository, in-depth lineage, and seamless team collaboration. The `Jw | Mar 15, 2024 | 9.8 | 85 | NO | YES |
CVE-2024-28254HIGH OpenMetadata is a unified platform for discovery, observability, and governance powered by a central metadata repository, in-depth lineage, and seamless team collaboration. The `A | Mar 15, 2024 | 8.8 | 63 | NO | YES |
CVE-2024-28253HIGH OpenMetadata is a unified platform for discovery, observability, and governance powered by a central metadata repository, in-depth lineage, and seamless team collaboration. `Compil | Mar 15, 2024 | 8.8 | 43 | NO | YES |
CVE-2024-28847HIGH OpenMetadata is a unified platform for discovery, observability, and governance powered by a central metadata repository, in-depth lineage, and seamless team collaboration. Similar | Mar 15, 2024 | 8.8 | 31 | NO | NO |
CVE-2024-28848HIGH OpenMetadata is a unified platform for discovery, observability, and governance powered by a central metadata repository, in-depth lineage, and seamless team collaboration. The `C | Mar 15, 2024 | 8.8 | 29 | NO | NO |
CVE-2025-50465HIGH OpenMetadata <=1.4.4 is vulnerable to SQL Injection. An attacker can extract information from the database in function listCount in the TestDefinitionDAO interface. The testPlatfor | Aug 8, 2025 | 8.8 | 28 | NO | NO |
CVE-2026-26010HIGH OpenMetadata is a unified metadata platform. Prior to 1.11.8, calls issued by the UI against /api/v1/ingestionPipelines leak JWTs used by ingestion-bot for certain services (Glue / | Feb 11, 2026 | 7.6 | 26 | NO | NO |
CVE-2026-22244HIGH OpenMetadata is a unified metadata platform. Versions prior to 1.11.4 are vulnerable to remote code execution via Server-Side Template Injection (SSTI) in FreeMarker email template | Jan 8, 2026 | 7.2 | 24 | NO | NO |
CVE-2024-55238HIGH OpenMetadata <=1.4.1 is vulnerable to SQL Injection. An attacker can extract information from the database in function listCount in the WorkflowDAO interface. The workflowtype and | Apr 17, 2025 | 8.8 | 24 | NO | NO |
CVE-2025-50467MEDIUM OpenMetadata <=1.4.4 is vulnerable to SQL Injection. An attacker can extract information from the database in function listCount in the TestDefinitionDAO interface. The supportedDa | Aug 8, 2025 | 6.5 | 23 | NO | NO |
Signals from CVEs in this vendor scope (12 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Open Metadata.
Media articles that mention a CVE ID that affects a product developed by Open Metadata — matched by CVE ID, not by vendor name.