Openfeature develops feature-flagging infrastructure, with its flagd product serving as a configuration and evaluation service for feature management across distributed applications. The vulnerability profile centers on resource-exhaustion risks, reflecting the stateful, networked nature of flag-evaluation services and their exposure to unbounded request or data-handling patterns. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Openfeature over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-31866HIGH flagd is a feature flag daemon with a Unix philosophy. Prior to 0.14.2, flagd exposes OFREP (/ofrep/v1/evaluate/...) and gRPC (evaluation.v1, evaluation.v2) endpoints for feature f | Mar 11, 2026 | 7.5 | 24 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Openfeature.
Media articles that mention a CVE ID that affects a product developed by Openfeature — matched by CVE ID, not by vendor name.