{"id":"CVE-2026-50775","aliases":[],"url":"https://o3.security/vulnerability/CVE-2026-50775","summary":"A blind SSRF attack in DataHub v.1.5.0.1 allows a remote attacker to execute arbitrary code via the server retrieving an image from a crafted URL, and it fails to return the content…","details":"A blind SSRF attack in DataHub v.1.5.0.1 allows a remote attacker to execute arbitrary code via the server retrieving an image from a crafted URL, and it fails to return the content or any errors directly.","published":"2026-08-17T19:16:31.873","modified":"2026-08-18T19:16:55.910","cvss":{"score":9.8,"severity":"CRITICAL","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[],"fix":null,"references":[{"type":"WEB","url":"https://datahub.com/"},{"type":"WEB","url":"https://github.com/Henkel-CyberVM/CVEs/tree/main/CVE-2026-50775"},{"type":"WEB","url":"https://github.com/Henkel-CyberVM/CVEs/tree/main/CVE-2026-50775"}],"provenance":{"sources":["OSV.dev","NVD","FIRST.org (EPSS)"],"lastVerified":"2026-08-18T19:16:55.910"}}