CVE-2026-100373
Descriptive record received from OpenCTI and minimised for consultation in the Intel portal.
- Sharing
- PUBLIC-OSINT
- Confidence
- 100
- Source
- The CVE Program
- Updated
- 26/09/2026 03:30
Description
OpenMetadata through 2.0.2 contains a server-side request forgery vulnerability in the URLValidator.validateURL function that fails to properly resolve DNS hostnames and validate internal addresses. Users permitted to create or update EventSubscription can set webhook destinations to internal hosts, allowing the server to send requests to private networks and cloud metadata endpoints while returning HTTP status codes that enable blind SSRF probing.
Aliases and classifications
Minimised technical details
No raw data- cisa kev
- False
- cvss score
- 4.1
- cvss vector
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:N/A:N
- cvss severity
- MEDIUM
Public references
- product
https://github.com/open-metadata/OpenMetadata - exploit
https://gist.github.com/naif-alfardan/8a69e0648e11b07abe63f949346179c1 - VulnCheck Advisory: OpenMetadata through 2.0.2 SSRF via Webhook URL Validation Bypass
https://www.vulncheck.com/advisories/openmetadata-through-2.0.2-ssrf-via-webhook-url-validation-bypass - patch
https://github.com/open-metadata/OpenMetadata/commit/8f44482ac89bad9227df5b7f79beca2efe50c05f - technical-description
https://github.com/open-metadata/OpenMetadata/blob/2.0.2-release/openmetadata-service/src/main/java/org/openmetadata/service/util/URLValidator.java - issue-tracking
https://github.com/open-metadata/OpenMetadata/issues/32592
Intel catalogue
The vulnerability is also available in the EudorIA editorial catalogue.
Open EudorIA analysisPresence in OpenCTI describes an intelligence correlation and does not, by itself, constitute evidence of compromise, legal attribution or operational guidance applicable without context verification.