DataGear through 6.0.0 contains a server-side request forgery vulnerability in the /dataSet/preview/Http endpoint that allows unauthenticated attackers to execute arbitrary HTTP requests by supplying a caller-controlled URI. Attackers can issue GET, POST, PUT, PATCH, or DELETE requests to internal endpoints and cloud metadata services, receiving full response bodies without authentication or validation.
References
Configurations
No configuration.
History
16 Sep 2026, 16:17
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://github.com/datageartech/datagear/issues/37 - |
16 Sep 2026, 15:19
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-09-16 15:19
Updated : 2026-09-16 16:17
NVD link : CVE-2026-92566
Mitre link : CVE-2026-92566
CVE.ORG link : CVE-2026-92566
JSON object : View
Products Affected
No product.
CWE
CWE-918
Server-Side Request Forgery (SSRF)
