PatchSiren

DataHub CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

CRITICAL DataHub CVE published 2026-08-17

CVE-2026-50775

A blind SSRF attack in DataHub v.1.5.0.1 allows a remote attacker to execute arbitrary code via the server retrieving an image from a crafted URL, and it fails to return the content or any errors directly. This vulnerability can lead to potential remote code execution via crafted URLs and SSRF attacks could lead to unauthorized access or data breaches. Defenders should prioritize verifying exposure of Dat [truncated]