<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Cpe:2.3:a:datagear:datagear:*:*:*:*:*:*:*:* - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/cpes/cpe2.3adatageardatagear/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Wed, 16 Sep 2026 15:52:15 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/cpes/cpe2.3adatageardatagear/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>DataGear Server-Side Request Forgery in /dataSet/preview/Http</title><link>https://feed.craftedsignal.io/briefs/2026-09-datagear-ssrf/</link><pubDate>Wed, 16 Sep 2026 15:52:15 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-datagear-ssrf/</guid><description>DataGear versions up to 6.0.0 contain an unauthenticated server-side request forgery vulnerability allowing attackers to perform arbitrary internal HTTP requests and exfiltrate response bodies.</description><content:encoded>&lt;p>DataGear through version 6.0.0 contains a critical server-side request forgery (SSRF) vulnerability located within the /dataSet/preview/Http endpoint. This vulnerability allows an unauthenticated remote attacker to force the DataGear application to initiate unauthorized HTTP requests to arbitrary targets, including internal network infrastructure, internal services, and cloud environment metadata services.&lt;/p>
&lt;p>The application fails to validate the user-supplied URI parameter before executing the request, enabling support for various HTTP methods such as GET, POST, PUT, PATCH, and DELETE. Successful exploitation results in the disclosure of internal network configuration, service responses, and sensitive data that is otherwise unreachable from the public internet. Because the application returns the full response body of the requested resource to the attacker, this flaw presents a high risk for data exfiltration and internal reconnaissance. Defenders must prioritize restricting outbound network access from the DataGear server and ensuring the application is updated once a patch is available.&lt;/p>
</content:encoded><category domain="severity">high</category><category domain="type">advisory</category></item></channel></rss>