All vulnerabilities

CVE-2026-61742 · GHSA-fm8p-53ww-hf6w

DBHub HTTP transport DNS rebinding allows unauthenticated browser-origin SQL execution

highCWE-306CWE-346
Vendor
bytebase
Package
@bytebase/dbhub npm
Affected
<= 0.22.4
Disclosed
2026-06-24
Credit
Avishai Gonen
dns-rebindingsqlihost-header