Untriaged
Permalink
CVE-2026-25644
7.5 HIGH
- CVSS version: 3.1
- Attack vector (AV): NETWORK
- Attack complexity (AC): LOW
- Privileges required (PR): NONE
- User interaction (UI): NONE
- Scope (S): UNCHANGED
- Confidentiality impact (C): HIGH
- Integrity impact (I): NONE
- Availability impact (A): NONE
Activity log
- Created suggestion
DataHub's LDAP Ingestion Source vulnerable to MITM attack through TLS downgrade
DataHub is an open-source metadata platform. Prior to version 1.3.1.8, the LDAP ingestion source is vulnerable to MITM attack through TLS downgrade. This issue has been patched in version 1.3.1.8.
References
Affected products
datahub
- ==< 1.3.1.8
Matching in nixpkgs
pkgs.python312Packages.cryptodatahub
Repository of cryptography-related data
-
nixos-unstable 1.0.0
pkgs.python313Packages.cryptodatahub
Repository of cryptography-related data
pkgs.python314Packages.cryptodatahub
Repository of cryptography-related data
Package maintainers
-
@Prince213 Sizhe Zhao <prc.zhao@outlook.com>
-
@OPNA2608 Cosima Neidahl <opna2608@protonmail.com>
-
@ethancedwards8 Ethan Carter Edwards <ethan@ethancedwards.com>
-
@fricklerhandwerk Valentin Gagarin <valentin@fricklerhandwerk.de>
-
@eljamm Fedi Jamoussi <fedi.jamoussi@protonmail.ch>
-
@wegank Weijia Wang <contact@weijia.wang>