Description
A blind SSRF attack in DataHub v.1.5.0.1 allows a remote attacker to execute arbitrary code via the server retrieving an image from a crafted URL, and it fails to return the content or any errors directly.
Published: 2026-08-17
Score: n/a
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A blind Server‑Side Request Forgery (SSRF) flaw exists in DataHub version 1.5.0.1, allowing an attacker who can trigger the image‑fetching routine to supply a crafted URL. When DataHub retrieves the image, it executes arbitrary code supplied by the attacker, yet the response or any error information is not returned to the requester, making detection difficult. The flaw enables remote code execution on the server that hosts DataHub, compromising confidentiality, integrity, and availability of the affected system.

Affected Systems

DataHub v.1.5.0.1 is affected. No additional vendor or product information is provided in the available data.

Risk and Exploitability

The vulnerability can be exploited from any remote system that can send requests to the vulnerable DataHub instance. No CVSS score or EPSS information is available. The flaw is listed as not in the CISA KEV catalog. Because the flaw allows remote code execution and lacks response feedback, the risk to exposed servers is high; however, exact likelihood cannot be quantified without EPSS or CVSS data. The likely attack vector is a remote attacker crafting a URL to trigger the image fetch endpoint from a client.

Generated by OpenCVE AI on August 17, 2026 at 19:34 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Verify whether DataHub v1.5.0.1 is deployed and assess the exposure surface for the image‑fetching functionality.
  • Upgrade DataHub to the latest version where the SSRF flaw has been addressed; if no patch is available, consider moving to a later release that removes the vulnerable image retrieval path.
  • If upgrading is not immediately possible, implement network controls to block outbound requests initiated by DataHub to untrusted URLs, or configure firewall rules to limit the scope of the SSRF attack surface.

Generated by OpenCVE AI on August 17, 2026 at 19:34 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 17 Aug 2026 20:00:00 +0000

Type Values Removed Values Added
Title Blind SSRF in DataHub Enables Remote Code Execution via Image Retrieval
Weaknesses CWE-918

Mon, 17 Aug 2026 19:45:00 +0000

Type Values Removed Values Added
First Time appeared Datahub
Datahub datahub
Vendors & Products Datahub
Datahub datahub

Mon, 17 Aug 2026 18:30:00 +0000

Type Values Removed Values Added
Description A blind SSRF attack in DataHub v.1.5.0.1 allows a remote attacker to execute arbitrary code via the server retrieving an image from a crafted URL, and it fails to return the content or any errors directly.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-08-17T18:11:11.783Z

Reserved: 2026-06-07T00:00:00.000Z

Link: CVE-2026-50775

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-17T19:16:31.873

Modified: 2026-08-17T19:16:31.873

Link: CVE-2026-50775

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-17T19:45:04Z

Weaknesses
  • CWE-918

    Server-Side Request Forgery (SSRF)