CVE-2026-63645 | OpenObserve up to 0.90.2 Server Configuration Serialization /config/runtime information disclosure

SecurityVulns

A vulnerability was found in OpenObserve up to 0.90.2. It has been declared as problematic. This issue affects some unknown processing of the file /config/runtime of the component Server Configuration Serialization. Such manipulation of the argument meta_postgres_dsn/meta_postgres_ro_dsn/meta_ddl_dsn/usage_reporting_creds leads to information disclosure.

This vulnerability is listed as CVE-2026-63645. The attack may be performed from remote. There is no available exploit.

It is recommended to upgrade the affected component.VulDB Recent EntriesRead More