TLS Downgrade Vulnerability in DataHub Metadata Platform
CVE-2026-25644
7.5HIGH
What is CVE-2026-25644?
The open-source metadata platform DataHub was found to be susceptible to a vulnerability that allows for man-in-the-middle (MITM) attacks due to a TLS downgrade mechanism in its LDAP ingestion source. This flaw permits an attacker to intercept and potentially manipulate communications by downgrading secure connections to a less secure state. Users are advised to upgrade to version 1.3.1.8 or later to mitigate these risks and enhance the security posture of their deployments.
Affected Version(s)
datahub < 1.3.1.8
