Security: datahub-project/datahub
Security Advisories
View known security vulnerabilities and report new vulnerabilities privately to maintainers.
-
Open Redirect Vulnerability in DataHub (BasePathRedirectFilter)GHSA-phm8-vwjg-f442 published
Feb 20, 2026 by david-leifkerModerate -
LDAP Ingestion Source vulnerable to MITM attack through TLS downgradeGHSA-j34h-x7qg-4qw5 published
Feb 4, 2026 by RyanHolstienHigh -
Stored XSS - UI v1 Sidebar DescriptionGHSA-8v62-ch9g-mvw9 published
May 29, 2025 by david-leifkerLow -
false positives: datahub-java dependenciesGHSA-8cr6-69rq-2mj8 published
Sep 20, 2024 by david-leifkerLow -
false positive: datahub-web-react dependenciesGHSA-grf6-rh4c-p2p6 published
Sep 20, 2024 by david-leifkerLow -
Privilege escalation through email sign-upGHSA-vj59-23ww-p6c8 published
Nov 13, 2023 by david-leifkerHigh -
Default Privileges allow for high level operations for low privileged usersGHSA-x3v6-r479-m4xv published
Jan 10, 2024 by RyanHolstienHigh -
CLI Debug Logs contain Sensitive informationGHSA-g8pc-2p86-8x73 published
Nov 13, 2023 by david-leifkerLow -
Vulnerable Analytics-Utils Dependency in DataHub FrontendGHSA-fmp6-j664-fqg5 published
Nov 14, 2023 by david-leifkerHigh -
Session Expiration MisconfigurationGHSA-75p8-rgh2-r9mx published
Nov 13, 2023 by david-leifkerModerate