PatchSiren

openobserve CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH openobserve CVE published 2026-04-07

CVE-2026-39361

The OpenObserve cloud-native observability platform is vulnerable to an issue in version 0.70.3 and earlier. The validate_enrichment_url function fails to block IPv6 addresses due to Rust's url crate returning them with surrounding brackets. An authenticated attacker can reach internal services blocked from external access, potentially retrieving IAM credentials via cloud metadata services or probing inte [truncated]