GHSA-fm8p-53ww-hf6w: DBHub HTTP transport DNS rebinding allows unauthenticated browser-origin SQL execution
Summary
DBHub version 0.21.2 has a security flaw in its HTTP mode that allows attackers to run database commands from a malicious website. The vulnerability uses DNS rebinding (a technique where an attacker's hostname switches its IP address to point to the victim's DBHub server), which bypasses the software's origin-checking protection. Because the check only compares hostnames instead of maintaining an explicit list of allowed hosts, both the attacker's hostname and the victim's DBHub server appear to match, allowing the malicious site to execute database operations without authentication.
Vulnerability Details
EPSS: 0.0%
Yes
September 24, 2026
Classification
Affected Vendors
Affected Packages
Original source: https://github.com/advisories/GHSA-fm8p-53ww-hf6w
First tracked: September 24, 2026 at 08:00 PM
Classified by LLM (prompt v3) · confidence: 75%