Security: datahub-project/datahub
Security Advisories
View known security vulnerabilities and report new vulnerabilities privately to maintainers.
-
DataHub OIDC REDIRECT_URL Cookie Deserialization VulnerabilityGHSA-rjf9-p49v-42c4 published
Apr 30, 2026 by RyanHolstienModerate -
Open Redirect Vulnerability in DataHub (redirect_uri)GHSA-3p57-xxv6-6wqp published
May 19, 2026 by david-leifkerModerate -
Open Redirect Vulnerability in DataHub (BasePathRedirectFilter)GHSA-phm8-vwjg-f442 published
Feb 20, 2026 by david-leifkerModerate -
LDAP Ingestion Source vulnerable to MITM attack through TLS downgradeGHSA-j34h-x7qg-4qw5 published
Feb 4, 2026 by RyanHolstienHigh -
Stored XSS - UI v1 Sidebar DescriptionGHSA-8v62-ch9g-mvw9 published
May 29, 2025 by david-leifkerLow -
false positives: datahub-java dependenciesGHSA-8cr6-69rq-2mj8 published
Sep 20, 2024 by david-leifkerLow -
false positive: datahub-web-react dependenciesGHSA-grf6-rh4c-p2p6 published
Sep 20, 2024 by david-leifkerLow -
Privilege escalation through email sign-upGHSA-vj59-23ww-p6c8 published
Nov 13, 2023 by david-leifkerHigh -
Default Privileges allow for high level operations for low privileged usersGHSA-x3v6-r479-m4xv published
Jan 10, 2024 by RyanHolstienHigh -
CLI Debug Logs contain Sensitive informationGHSA-g8pc-2p86-8x73 published
Nov 13, 2023 by david-leifkerLow