CVE-2026-25644 Details
Description
DataHub is an open-source metadata platform. Prior to version 1.3.1.8, the LDAP ingestion source is vulnerable to MITM attack through TLS downgrade. This issue has been patched in version 1.3.1.8.
A vulnerability in the LDAP ingestion source of DataHub, prior to version 1.3.1.8, allows for man-in-the-middle (MITM) attacks through a TLS downgrade. The issue arises because the LDAP source improperly validates TLS certificates, accepting connections even when validation fails. This flaw enables an attacker to intercept LDAPS credentials by presenting a rogue certificate. The vulnerability is exacerbated by the absence of a configuration option to specify trusted CA certificates, and the hardcoded setting that ignores validation failures.
Users should update to DataHub version 1.3.1.8 or later. Additionally, ensure that the DataHub deployment only exposes necessary external services, ideally within a fully internal network between DataHub and the LDAP deployment.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Feb 9, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/datahub-project/datahub/security/advisories/GHSA-j34h-x7qg-4qw5 | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-295 | Improper Certificate Validation | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| datahub datahub | < 1.3.1.8 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Feb 20, 2026 | Initial Analysis | [email protected] |
| Feb 6, 2026 | New CVE Received | [email protected] |