CVE-2026-63645

Source
https://cve.org/CVERecord?id=CVE-2026-63645
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-63645.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-63645
Aliases
  • GHSA-v496-g5c9-vqxw
Published
2026-09-24T17:39:42Z
Modified
2026-09-26T03:46:51Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N CVSS Calculator
Summary
OpenObserve: Unauthenticated /config/runtime endpoint exposes PostgreSQL database credentials
Details

OpenObserve is a cloud-native observability platform. Prior to 0.90.3, OpenObserve registers the /config/runtime endpoint without authentication and serializes the complete server configuration after applying the hide_sensitive_fields keyword filter. The filter does not recognize dsn or creds field names, so meta_postgres_dsn, meta_postgres_ro_dsn, meta_ddl_dsn, and usage_reporting_creds can be returned in plaintext to an unauthenticated network client. PostgreSQL deployments can expose database credentials, and the same response can disclose the root administrator email address, internal NATS address, filesystem layout, and other deployment details. This issue is fixed in version 0.90.3.

Database specific
{
    "cna_assigner":  "GitHub_M",
    "cwe_ids":  [
        "CWE-200"
    ],
    "osv_generated_from":  "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/63xxx/CVE-2026-63645.json"
}
References

Affected packages

Git / github.com/openobserve/openobserve

Affected ranges

Type
GIT
Repo
https://github.com/openobserve/openobserve
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Fixed
Database specific
Show details
{
    "extracted_events":  [
        {
            "introduced":  "0"
        },
        {
            "fixed":  "0.90.3"
        }
    ],
    "source":  [
        "AFFECTED_FIELD",
        "REFERENCES"
    ]
}

Affected versions

v0.*
v0.1.5
v0.1.6
v0.1.7
v0.1.8
v0.10.0
v0.10.1
v0.10.2
v0.10.2-rc1
v0.10.3
v0.10.4
v0.10.5
v0.10.6
v0.10.6-rc1
v0.10.6-rc2
v0.10.7
v0.10.7-rc1
v0.10.7-rc2
v0.10.7-rc3
v0.10.8
v0.10.8-rc1
v0.10.8-rc2
v0.10.8-rc3
v0.10.8-rc4
v0.10.8-rc5
v0.10.9
v0.10.9-rc1
v0.10.9-rc2
v0.10.9-rc3
v0.10.9-rc4
v0.11.0
v0.11.0-rc1
v0.11.0-rc2
v0.11.0-rc3
v0.12.0
v0.12.0-rc1
v0.12.0-rc2
v0.12.1
v0.13.0
v0.13.0-rc1
v0.13.0-rc2
v0.13.1
v0.13.1-rc1
v0.13.1-rc2
v0.13.1-rc3
v0.13.2-rc1
v0.13.2-rc2
v0.13.2-rc3
v0.13.2-rc4
v0.14.0
v0.14.1
v0.14.1-rc1
v0.14.1-rc2
v0.14.1-rc3
v0.14.2
v0.14.3
v0.14.3-rc1
v0.14.3-rc2
v0.14.3-rc3
v0.14.4
v0.14.5
v0.14.5-rc1
v0.14.5-rc2
v0.14.5-rc3
v0.14.5-rc4
v0.14.5-rc5
v0.14.5-rc6
v0.14.6
v0.14.6-rc1
v0.14.6-rc2
v0.14.6-rc3
v0.14.6-rc4
v0.14.6-rc5
v0.14.6-rc6
v0.14.6-rc7
v0.14.6-rc8
v0.14.7
v0.15.0
v0.15.0-rc1
v0.15.0-rc2
v0.15.0-rc3
v0.15.0-rc5
v0.16.0-rc1
v0.2.0
v0.20.0-rc1
v0.3.0
v0.3.1
v0.3.2
v0.30.0-rc1
v0.4.1
v0.4.2
v0.4.3
v0.4.4
v0.4.5
v0.4.6
v0.4.7
v0.4.8
v0.4.9
v0.40.0-rc1
v0.5.0
v0.5.1
v0.5.2
v0.5.3
v0.50.0-rc1
v0.6.0
v0.6.1
v0.6.2
v0.6.3
v0.6.4
v0.60.0-rc1
v0.7.0
v0.7.0-rc1
v0.7.0-rc2
v0.7.2
v0.7.2-rc1
v0.70.0-rc1
v0.8.0
v0.8.0-rc1
v0.8.0-rc2
v0.8.1
v0.8.1-rc1
v0.8.1-rc2
v0.8.2-rc1
v0.8.2-rc2
v0.8.2-rc3
v0.8.2-rc4
v0.8.2-rc5
v0.8.2-rc6
v0.8.2-rc7
v0.80.0-rc1
v0.80.0-rc4
v0.9.0-rc1
v0.9.0-rc2
v0.9.0-rc3
v0.9.0-rc4
v0.9.0-rc5
v0.9.0-rc6
v0.9.0-rc7
v0.9.0-rc8
v0.9.1
v0.9.2-rc1
v0.90.0
v0.90.0-rc1
v0.90.0-rc2
v0.90.0-rc3
v0.90.0-rc4
v0.90.1
v0.90.2

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-63645.json"