CVE-2026-50775
Received Received - Intake

Blind SSRF in DataHub v1.5.0.1 Allows Remote Code Execution

Vulnerability report for CVE-2026-50775, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-17

Last updated on: 2026-08-17

Assigner: MITRE

Description

A blind SSRF attack in DataHub v.1.5.0.1 allows a remote attacker to execute arbitrary code via the server retrieving an image from a crafted URL, and it fails to return the content or any errors directly.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-17
Last Modified
2026-08-17
Generated
2026-08-17
AI Q&A
2026-08-17
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
datahub datahub 1.5.0.1

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-50775 is a Blind Server-Side Request Forgery (SSRF) vulnerability in DataHub version 1.5.0.1. It allows a remote attacker to trick the server into making an outbound request to a crafted URL without returning the content or errors directly. The attacker can use an external server like Burp Collaborator to detect if the target server initiates a request.

Detection Guidance

To detect this Blind SSRF vulnerability in DataHub v1.5.0.1, use Burp Collaborator to check if the server initiates outbound requests to external URLs. Configure Burp Suite to monitor for interactions with your Burp Collaborator server when the application processes user-supplied image URLs.

Impact Analysis

This vulnerability could allow an attacker to perform unauthorized actions on behalf of the server, such as accessing internal resources, exfiltrating data, or interacting with other systems. Since the server does not return errors or content, the attack may go unnoticed, increasing the risk of prolonged exploitation.

Compliance Impact

The blind SSRF vulnerability in DataHub v1.5.0.1 could potentially impact compliance with GDPR and HIPAA by enabling unauthorized data exfiltration or access to internal systems. SSRF attacks may allow attackers to interact with internal services, which could lead to data breaches or unauthorized data processing, violating GDPR's data protection principles or HIPAA's safeguards for protected health information.

Mitigation Strategies

Upgrade DataHub to the latest patched version to address the Blind SSRF issue. If immediate upgrading is not possible, restrict network access for the DataHub server to prevent outbound requests to untrusted domains.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-50775. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart