HIGH🇵🇱 Wersja polska

CVE-2026-25644

CVSS 7.5v3.1pub. 2026-02-06upd. 2026-02-20

DataHub is an open-source metadata platform. Prior to version 1.3.1.8, the LDAP ingestion source is vulnerable to MITM attack through TLS downgrade. This issue has been patched in version 1.3.1.8.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
  • Datahub

    APP
    Datahub
    < 1.3.1.8
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2022-39366CRITICAL9.9PL ✓same product

DataHub: Pominięcie weryfikacji podpisu JWT umożliwia auth bypass

CVE-2023-25557HIGH7.5same product

DataHub is an open-source metadata platform. The DataHub frontend acts as a proxy able to forward any REST or ...

CVE-2023-25559HIGH8.2same product

DataHub is an open-source metadata platform. When not using authentication for the metadata service, which is ...

CVE-2023-25560HIGH8.2same product

DataHub is an open-source metadata platform. The AuthServiceClient which is responsible for creation of new ac...

CVE-2026-44501MEDIUM4.3same product

DataHub to open-source'owa platforma metadanych. Przed wersją 1.5.0.3 frontend DataHub (datahub-frontend-react...