OpenObserve Cloud-Native Observability Platform Vulnerability
CVE-2026-63645
7.5HIGH
What is CVE-2026-63645?
OpenObserve, a cloud-native observability platform, previously registered the /config/runtime endpoint without proper authentication. This security oversight allowed unauthenticated network clients to access serialized server configurations that included sensitive information. Despite the implementation of the hide_sensitive_fields keyword filter, it failed to obscure specific fields such as dsn and creds, enabling attackers to retrieve database credentials, internal communication addresses, and valuable system details in plaintext. This significant vulnerability has been addressed in version 0.90.3, which reinforces security measures to prevent unauthorized access.
Affected Version(s)
openobserve < 0.90.3
