CVEFinder.io

CVE-2026-25644

⚠️ high
🔍 Scan for this CVE
Summary

DataHub is an open-source metadata platform. Prior to version 1.3.1.8, the LDAP ingestion source is vulnerable to MITM attack through TLS downgrade. This issue has been patched in version 1.3.1.8.

CVSS Score
7.5
High
EPSS Score
0.0
Exploit Probability
Published Date
2026-02-06
First Seen: 2026-02-07
📊 Relative Risk Intelligence

This CVE is Moderate Risk - more severe than 68.0% of all 348,756 vulnerabilities in our database.

#111,664
Above average severity
Severity Percentile
🎯 CISA SSVC Assessment Updated: Feb 9, 2026
🔍 Exploitation Status
None
No known exploits
⚙️ Automatable
YES
Can be exploited automatically
💥 Technical Impact
Partial
Limited system impact
SSVC data provided by CISA
Last Modified 2026-02-20
Source NVD 🔗
CVSS Vector 3.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CWE IDs (Weakness Types)

📦 Affected Products 1

🔗 References 1

🔗 Related CVEs 6

CVE ID Severity CVSS EPSS Summary Published
CVE-2026-44501 🔶 medium 4.3 0.0 DataHub is an open-source metadata platform. Prior to 1.5.0.3, The DataHub frontend (datahub-frontend-react) deserialize... 2026-05-14
CVE-2023-25557 ⚠️ high 7.5 0.6 DataHub is an open-source metadata platform. The DataHub frontend acts as a proxy able to forward any REST or GraphQL re... 2023-02-11
CVE-2023-25559 ⚠️ high 8.2 0.1 DataHub is an open-source metadata platform. When not using authentication for the metadata service, which is the defaul... 2023-02-11
CVE-2023-25560 ⚠️ high 8.2 0.2 DataHub is an open-source metadata platform. The AuthServiceClient which is responsible for creation of new accounts, ve... 2023-02-11
CVE-2023-25561 🔶 medium 5.7 0.2 DataHub is an open-source metadata platform. In the event a system is using Java Authentication and Authorization Servic... 2023-02-11
CVE-2023-25562 🔶 medium 6.9 0.0 DataHub is an open-source metadata platform. In versions of DataHub prior to 0.8.45 Session cookies are only cleared on ... 2023-02-11
These CVEs affect the same products