CVE-2026-100373

CVE-2026-100373 published: OpenMetadata through 2.0.2 contains a server-side request forgery vulnerability in the URLValidator.validateURL function that fails to properly resolve DNS hostnames and validate internal addresses. Users permitted to create or update EventSubscription can ...

View full NVD advisory → ← Back to CVE watch