Openmetadata
Vendor:
First CVE: Mar 15, 2024 · Active for 2 years
12
Total CVEs
More Total CVEs than 90% of tracked products
4.0
Avg CVEs / Year
Higher CVE frequency than 83% of tracked products
8.1
Avg CVSS
Higher Avg CVSS than 70% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Openmetadata over time
Volume of CVEsAvg CVSS Base Score
First CVE
Mar 15, 2024
2 years ago
Most Recent CVE
Feb 11, 2026
163 days ago
CVE Severity & Scoring
Openmetadata12 CVEs
25%
67%
8%
All CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network12 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low12 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None12 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low8 (66.7%)
High1 (8.3%)
None3 (25.0%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (12 CVEs).
12 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-28255CRITICAL OpenMetadata is a unified platform for discovery, observability, and governance powered by a central metadata repository, in-depth lineage, and seamless team collaboration. The `Jw | Mar 15, 2024 | 9.8 | 85 | NO | YES |
CVE-2024-28254HIGH OpenMetadata is a unified platform for discovery, observability, and governance powered by a central metadata repository, in-depth lineage, and seamless team collaboration. The `A | Mar 15, 2024 | 8.8 | 63 | NO | YES |
CVE-2024-28253HIGH OpenMetadata is a unified platform for discovery, observability, and governance powered by a central metadata repository, in-depth lineage, and seamless team collaboration. `Compil | Mar 15, 2024 | 8.8 | 43 | NO | YES |
CVE-2024-28847HIGH OpenMetadata is a unified platform for discovery, observability, and governance powered by a central metadata repository, in-depth lineage, and seamless team collaboration. Similar | Mar 15, 2024 | 8.8 | 31 | NO | NO |
CVE-2024-28848HIGH OpenMetadata is a unified platform for discovery, observability, and governance powered by a central metadata repository, in-depth lineage, and seamless team collaboration. The `C | Mar 15, 2024 | 8.8 | 29 | NO | NO |
CVE-2025-50465HIGH OpenMetadata <=1.4.4 is vulnerable to SQL Injection. An attacker can extract information from the database in function listCount in the TestDefinitionDAO interface. The testPlatfor | Aug 8, 2025 | 8.8 | 28 | NO | NO |
CVE-2026-26010HIGH OpenMetadata is a unified metadata platform. Prior to 1.11.8, calls issued by the UI against /api/v1/ingestionPipelines leak JWTs used by ingestion-bot for certain services (Glue / | Feb 11, 2026 | 7.6 | 26 | NO | NO |
CVE-2026-22244HIGH OpenMetadata is a unified metadata platform. Versions prior to 1.11.4 are vulnerable to remote code execution via Server-Side Template Injection (SSTI) in FreeMarker email template | Jan 8, 2026 | 7.2 | 24 | NO | NO |
CVE-2024-55238HIGH OpenMetadata <=1.4.1 is vulnerable to SQL Injection. An attacker can extract information from the database in function listCount in the WorkflowDAO interface. The workflowtype and | Apr 17, 2025 | 8.8 | 24 | NO | NO |
CVE-2025-50467MEDIUM OpenMetadata <=1.4.4 is vulnerable to SQL Injection. An attacker can extract information from the database in function listCount in the TestDefinitionDAO interface. The supportedDa | Aug 8, 2025 | 6.5 | 23 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (12 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
2 CVEs
16.7% of CVEs· 97th percentile
Nuclei
2 CVEs
16.7% of CVEs· 98th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (12 CVEs).
Media Mentions
Signals from CVEs in this product scope (12 CVEs).
Top CNAs Publishing CVEs For Openmetadata
Top CWEs
Versions
No cataloged versions.