Openobserve

    Dashboard / Vendors

    Products: 1
    Vulnerabilities: 8
    Known Exploited: 0
    2
    Critical Level Threats
    4
    High Level Threats
    0
    Medium Level Threats
    1
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2026-39361

    OpenObserve has a SSRF Protection Bypass via IPv6 Bracket Notation in validate_enrichment_url

    Last Modified: Apr 15, 2026
    Published: Apr 07, 2026

    CVE-2025-66223

    OpenObserve's Invite Token Lifecycle Misconfiguration

    Last Modified: Apr 15, 2026
    Published: Nov 29, 2025

    CVE-2025-64744

    OpenObserve Vulnerable to HTML Injection in Organization Invitation Emails

    Last Modified: Apr 15, 2026
    Published: Nov 13, 2025

    CVE-2024-55954

    OpenObserve Improper Authorization Allows Admin User to Remove Root User

    Last Modified: Apr 15, 2026
    Published: Jan 16, 2025

    CVE-2024-41809

    OpenObserve Cross-site Scripting (XSS) vulnerability in `openobserve/web/src/views/MemberSubscription.vue`

    Last Modified: Nov 21, 2024
    Published: Jul 25, 2024
    Items Per Page