PT-2026-99101 · Unknown · Openmetadata

·

CVE-2026-100373

·

Published

2026-09-25

·

Updated

2026-09-25

CVSS v3.1

4.1

Medium

VectorAV:N/AC:L/PR:H/UI:N/S:C/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions OpenMetadata versions prior to 2.0.3
Description An issue exists in the URLValidator.validateURL() function where DNS hostnames are not properly resolved and internal addresses are not correctly validated. This allows users with permissions to create or update EventSubscription to configure webhook destinations pointing to internal hosts. Consequently, the server can be induced to send requests to private networks and cloud metadata endpoints, with the returned HTTP status codes facilitating blind Server-Side Request Forgery (SSRF) probing, a technique used to confirm the existence of internal services without seeing the direct response body.
Recommendations Update OpenMetadata to version 2.0.3 or later. Restrict the ability to create or update EventSubscription to trusted administrators only.

Exploit

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-100373

Affected Products

Openmetadata