Openobserve is a data observability and log analytics platform with a narrow product scope that has attracted security research focus disproportionate to its disclosure volume. The vendor's vulnerability profile centers on authentication and access-control weaknesses—including improper authentication, authorization, privilege management, and cross-site scripting—which are characteristic of web-facing analytics and multi-tenant log-ingestion systems; current severity and exploitation figures are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Openobserve over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-39361HIGH OpenObserve is a cloud-native observability platform. In 0.70.3 and earlier, the validate_enrichment_url function in src/handler/http/request/enrichment_table/mod.rs fails to block | Apr 7, 2026 | 7.7 | 26 | NO | NO |
CVE-2024-24830HIGH OpenObserve is a observability platform built specifically for logs, metrics, traces, analytics, designed to work at petabyte scale. A vulnerability has been identified in the "/ap | Feb 8, 2024 | 8.8 | 26 | NO | NO |
CVE-2024-41809MEDIUM OpenObserve is an open-source observability platform. Starting in version 0.4.4 and prior to version 0.10.0, OpenObserve contains a cross-site scripting vulnerability in line 32 of | Jul 25, 2024 | 6.1 | 19 | NO | NO |
CVE-2024-41808MEDIUM The OpenObserve open-source observability platform provides the ability to filter logs in a dashboard by the values uploaded in a given log. However, all versions of the platform t | Jul 25, 2024 | 5.4 | 19 | NO | NO |
CVE-2024-25106MEDIUM OpenObserve is a observability platform built specifically for logs, metrics, traces, analytics, designed to work at petabyte scale. A critical vulnerability has been identified in | Feb 8, 2024 | 6.5 | 17 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Openobserve.
Media articles that mention a CVE ID that affects a product developed by Openobserve — matched by CVE ID, not by vendor name.