Executive brief
DataHub is an open-source metadata platform used by organizations to manage and discover data assets. A security flaw in its login process allows an attacker with a valid account to send malicious data through a browser cookie. This could allow an attacker to scan internal company networks or potentially take control of the server, leading to unauthorized access to sensitive metadata or internal systems.
Technical details
The DataHub frontend (datahub-frontend-react) fails to validate the integrity of the REDIRECT_URL HTTP cookie during the OpenID Connect (OIDC) callback flow. The application deserializes Java objects from this cookie without using HMAC or encryption (CWE-502). An attacker with a valid account in the configured OIDC identity provider can exploit the GET /callback/oidc endpoint by providing a crafted cookie. This can result in blind Server-Side Request Forgery (SSRF) for internal port scanning, and potentially Remote Code Execution (RCE) if suitable gadget chains are present in the classpath. The vulnerability is addressed in version 1.5.0.3.
Affected products
- LinkedIn DataHub < 1.5.0.3
Timeline
- 2026-04-30: advisory: GitHub Security Advisory published
- 2026-05-14: disclosed: CVE published to NVD