{"data":{"id":"0b2f6ebf-49ee-4c5e-bcd1-3171d73af92f","title":"GHSA-fm8p-53ww-hf6w: DBHub HTTP transport DNS rebinding allows unauthenticated browser-origin SQL execution","summary":"DBHub version 0.21.2 has a security flaw in its HTTP mode that allows attackers to run database commands from a malicious website. The vulnerability uses DNS rebinding (a technique where an attacker's hostname switches its IP address to point to the victim's DBHub server), which bypasses the software's origin-checking protection. Because the check only compares hostnames instead of maintaining an explicit list of allowed hosts, both the attacker's hostname and the victim's DBHub server appear to match, allowing the malicious site to execute database operations without authentication.","solution":"N/A -- no mitigation discussed in source.","labels":["security"],"sourceUrl":"https://github.com/advisories/GHSA-fm8p-53ww-hf6w","publishedAt":"2026-09-24T19:36:57.000Z","cveId":"CVE-2026-61742","cweIds":null,"cvssScore":null,"cvssSeverity":"critical","severity":"critical","attackType":[],"issueType":"vulnerability","affectedPackages":["@bytebase/dbhub@<= 0.22.4 (fixed: 0.22.5)"],"affectedVendors":[],"affectedVendorsRaw":["DBHub"],"classifierModel":"claude-haiku-4-5-20251001","classifierPromptVersion":"v3","cvssVector":null,"attackVector":null,"attackComplexity":null,"privilegesRequired":null,"userInteraction":null,"exploitMaturity":"unknown","epssScore":0,"patchAvailable":true,"disclosureDate":"2026-09-24T19:36:57.000Z","capecIds":null,"crossRefCount":0,"attackSophistication":"moderate","impactType":["confidentiality","integrity"],"aiComponentTargeted":"api","llmSpecific":false,"classifierConfidence":0.75,"researchCategory":null,"atlasIds":null}}