Datahub is a metadata management and data cataloging platform that, despite a narrow product footprint centered on its core application and Helm deployment configurations, ranks among the more prominent vendors in the vulnerability landscape. Vulnerabilities affecting this vendor skew strongly toward critical-severity outcomes and recur through authentication, deserialization, and certificate-validation weaknesses that reflect the platform's role ingesting and serving metadata across distributed systems. Defenders should treat Datahub deployment advisories with high priority; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Datahub over time
Signals from CVEs in this vendor scope (14 CVEs).
14 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-25561CRITICAL DataHub is an open-source metadata platform. In the event a system is using Java Authentication and Authorization Service (JAAS) authentication and that system is given a configura | Feb 11, 2023 | 9.8 | 29 | NO | NO |
CVE-2023-25560CRITICAL DataHub is an open-source metadata platform. The AuthServiceClient which is responsible for creation of new accounts, verifying credentials, resetting them or requesting access tok | Feb 11, 2023 | 9.8 | 29 | NO | NO |
CVE-2023-25558HIGH DataHub is an open-source metadata platform. When the DataHub frontend is configured to authenticate via SSO, it will leverage the pac4j library. The processing of the `id_token` i | Feb 11, 2023 | 8.8 | 27 | NO | NO |
CVE-2023-25557CRITICAL DataHub is an open-source metadata platform. The DataHub frontend acts as a proxy able to forward any REST or GraphQL requests to the backend. The goal of this proxy is to perform | Feb 11, 2023 | 9.1 | 27 | NO | NO |
CVE-2026-44501HIGH DataHub is an open-source metadata platform. Prior to 1.5.0.3, The DataHub frontend (datahub-frontend-react) deserializes attacker-controlled Java objects from the REDIRECT_URL HTT | May 14, 2026 | 7.1 | 26 | NO | NO |
CVE-2024-22409HIGH DataHub is an open-source metadata platform. In affected versions a low privileged user could remove a user, edit group members, or edit another user's profile information. The def | Jan 16, 2024 | 8.8 | 24 | NO | NO |
CVE-2023-47629HIGH DataHub is an open-source metadata platform. In affected versions sign-up through an invite link does not properly restrict users from signing up as privileged accounts. If a user | Nov 14, 2023 | 8.0 | 24 | NO | NO |
CVE-2023-25562CRITICAL DataHub is an open-source metadata platform. In versions of DataHub prior to 0.8.45 Session cookies are only cleared on new sign-in events and not on logout events. Any authenticat | Feb 11, 2023 | 9.8 | 24 | NO | NO |
CVE-2023-25559HIGH DataHub is an open-source metadata platform. When not using authentication for the metadata service, which is the default configuration, the Metadata service (GMS) will use the X-D | Feb 11, 2023 | 8.1 | 24 | NO | NO |
CVE-2022-39366CRITICAL DataHub is an open-source metadata platform. Prior to version 0.8.45, the `StatelessTokenService` of the DataHub metadata service (GMS) does not verify the signature of JWT tokens. | Oct 28, 2022 | 9.8 | 24 | NO | NO |
Signals from CVEs in this vendor scope (14 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Datahub.
Media articles that mention a CVE ID that affects a product developed by Datahub — matched by CVE ID, not by vendor name.