Junglewise Threat Intelligence

CVE-2026-50775: DataHub blind SSRF in image retrieval

CVE-2026-50775 · Severity: critical · CVSS 9.8 · Published 2026-08-17

Executive brief

DataHub is an AI-powered data discovery and governance platform used by enterprises to manage their data estates. A blind SSRF vulnerability in version 1.5.0.1 allows remote attackers to trick the server into making requests to internal or external systems by supplying crafted image URLs, potentially leading to arbitrary code execution and unauthorized access to sensitive internal infrastructure.

Technical details

A blind server-side request forgery (SSRF) vulnerability exists in DataHub v1.5.0.1's image retrieval functionality. The vulnerable component fails to properly validate or sanitize user-supplied image URLs, allowing an attacker to specify URLs pointing to internal systems or arbitrary external servers. The vulnerability is "blind" because the server does not return the content of the retrieved resource or error messages to the attacker, but the attacker can still infer that a request was made (via out-of-band channels like Burp Collaborator). This permits attackers to scan internal networks, access metadata services, and potentially chain the SSRF into remote code execution. The attack requires network access to the DataHub application and the ability to supply a crafted URL via the image retrieval endpoint. An upstream fix has been submitted to the DataHub project.

Affected products

  • DataHub DataHub 1.5.0.1

Timeline

  • 2026-08-17: disclosed

References