Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

datahub — Vulnerabilities & Security Advisories 16

All 16 CVE vulnerabilities found in datahub, with AI-generated Chinese analysis, references, and POCs.

This page aggregates vulnerability data for the DataHub product, categorized by specific weakness types and security tags. The collection covers historical security defects associated with this data integration platform, spanning multiple years of advisory records. By analyzing the compiled data, users can track the vendor's published security advisories, understand recurring weakness classes such as injection flaws or authentication failures, and review the complete vulnerability history of the DataHub product. This resource supports security teams in assessing the current risk posture of DataHub deployments by revealing patterns in past incidents and their resolution status. The aggregation facilitates deeper analysis of how specific code weaknesses have historically impacted the product, enabling organizations to prioritize remediation efforts based on frequency and severity trends observed in the dataset.

Vendor: datahub-project

CVE ID Title CVSS Severity Published
CVE-2026-44501 DataHub OIDC REDIRECT_URL Cookie Deserialization Vulnerability CWE-502 4.3 Medium 2026-05-14
CVE-2026-25644 DataHub's LDAP Ingestion Source vulnerable to MITM attack through TLS downgrade CWE-295 7.5 High 2026-02-06
CVE-2024-22409 Default Privileges allow for high level operations for low privileged users in datahub CWE-276 7.5 High 2024-01-16
CVE-2023-47640 Insecure Use of HMAC-SHA1 For Session Signing in datahub CWE-327 6.4 Medium 2023-11-14
CVE-2023-47628 Session Expiration Misconfiguration in datahub CWE-613 4.2 Medium 2023-11-14
CVE-2023-47629 Privilege escalation through email sign-up in datahub CWE-269 7.1 High 2023-11-14
CVE-2023-25557 Server-Side Request Forgery in DataHub CWE-918 7.5 High 2023-02-10
CVE-2023-25558 Deserialization of untrusted data in DataHub CWE-502 7.5 High 2023-02-10
CVE-2023-25559 System account impersonation in DataHub CWE-287 8.2 High 2023-02-10
CVE-2023-25560 JSON Injection in DataHub CWE-913 8.2 High 2023-02-10
CVE-2023-25561 Login fail open on JAAS misconfiguration in DataHub CWE-755 5.7 Medium 2023-02-10
CVE-2023-25562 Failure to Invalidate Session on Logout in DataHub CWE-613 6.9 Medium 2023-02-10
CVE-2022-39366 DataHub missing JWT signature check CWE-303 9.9 Critical 2022-10-28
CVE-2014-2352 Cogent DataHub Path Traversal CWE-22 9.1 - 2014-05-30
CVE-2014-2353 Cogent DataHub XSS CWE-80 6.1 - 2014-05-30
CVE-2014-2354 Cogent DataHub Use of Password Hash With Insufficient Computational Effort CWE-916 9.8 - 2014-05-30

All 16 known CVE vulnerabilities affecting datahub with full Chinese analysis, references, and POCs where available.