CVE-2026-39361 | OpenObserve up to 0.70.3 mod.rs validate_enrichment_url server-side request forgery (GHSA-gcwf-3p7h-wm79)
A vulnerability marked as critical has been reported in OpenObserve up to 0.70.3. This impacts the function validate_enrichment_url of the file src/handler/http/request/enrichment_table/mod.rs. Performing a manipulation results in server-side request forgery.
This vulnerability is reported as CVE-2026-39361. The attack is possible to be carried out remotely. No exploit exists.
To fix this issue, it is recommended to deploy a patch.