Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-63645— OpenObserve: Unauthenticated /config/runtime endpoint exposes PostgreSQL database credentials

Quick assessment

Affected
openobserve openobserve
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

OpenObserve 是一个云原生可观测性平台。在 0.90.3 版本之前,OpenObserve 在不进行身份验证的情况下注册了 端点,并在应用 关键字过滤器之后序列化完整的服务器配置。该过滤器无法识别 或 字段名称,因此 、 、 和 等敏感信息会以明文形式返回给未经认证的远程网络客户端。对于 PostgreSQL 部署,这将导致数据库凭据暴露,同时相同的响应还会泄露根管理员邮箱地址、内部 NATS 地址、文件系统布局以及其他部署细节。此问题已在 0.90.3 版本中修复。

CVSS 7.5 · High EPSS 0.33% · P24

Possible ATT&CK Techniques 1 AI

T1530 · Data from Cloud Storage

Affected Version Matrix 1

VendorProduct Version RangeStatus
openobserve openobserve < 0.90.3 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-63645

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
OpenObserve: Unauthenticated /config/runtime endpoint exposes PostgreSQL database credentials
Source: CVE Program / CVE List V5
Vulnerability Description
OpenObserve is a cloud-native observability platform. Prior to 0.90.3, OpenObserve registers the /config/runtime endpoint without authentication and serializes the complete server configuration after applying the hide_sensitive_fields keyword filter. The filter does not recognize dsn or creds field names, so meta_postgres_dsn, meta_postgres_ro_dsn, meta_ddl_dsn, and usage_reporting_creds can be returned in plaintext to an unauthenticated network client. PostgreSQL deployments can expose database credentials, and the same response can disclose the root administrator email address, internal NATS address, filesystem layout, and other deployment details. This issue is fixed in version 0.90.3.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
信息暴露
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
openobserve openobserve < 0.90.3 -

II. Public POCs for CVE-2026-63645

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-63645

请登录查看更多情报信息。

Patches & Fixes for CVE-2026-63645 (2)

Vendor Advisories for CVE-2026-63645 (1)

Vendor Pages for CVE-2026-63645 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-63645

No comments yet


Leave a comment