HIGH
openobserve
CVE published 2026-04-07
CVE-2026-39361
The OpenObserve cloud-native observability platform is vulnerable to an issue in version 0.70.3 and earlier. The validate_enrichment_url function fails to block IPv6 addresses due to Rust's url crate returning them with surrounding brackets. An authenticated attacker can reach internal services blocked from external access, potentially retrieving IAM credentials via cloud metadata services or probing inte [truncated]