{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/vendors/datagear/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:datagear:datagear:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":8.2,"id":"CVE-2026-92566"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["DataGear (\u003c= 6.0.0)"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["DataGear"],"content_html":"\u003cp\u003eDataGear through version 6.0.0 contains a critical server-side request forgery (SSRF) vulnerability located within the /dataSet/preview/Http endpoint. This vulnerability allows an unauthenticated remote attacker to force the DataGear application to initiate unauthorized HTTP requests to arbitrary targets, including internal network infrastructure, internal services, and cloud environment metadata services.\u003c/p\u003e\n\u003cp\u003eThe application fails to validate the user-supplied URI parameter before executing the request, enabling support for various HTTP methods such as GET, POST, PUT, PATCH, and DELETE. Successful exploitation results in the disclosure of internal network configuration, service responses, and sensitive data that is otherwise unreachable from the public internet. Because the application returns the full response body of the requested resource to the attacker, this flaw presents a high risk for data exfiltration and internal reconnaissance. Defenders must prioritize restricting outbound network access from the DataGear server and ensuring the application is updated once a patch is available.\u003c/p\u003e\n","date_modified":"2026-09-16T15:52:15Z","date_published":"2026-09-16T15:52:15Z","id":"https://feed.craftedsignal.io/briefs/2026-09-datagear-ssrf/","summary":"DataGear versions up to 6.0.0 contain an unauthenticated server-side request forgery vulnerability allowing attackers to perform arbitrary internal HTTP requests and exfiltrate response bodies.","title":"DataGear Server-Side Request Forgery in /dataSet/preview/Http","url":"https://feed.craftedsignal.io/briefs/2026-09-datagear-ssrf/"}],"language":"en","title":"CraftedSignal Threat Feed - DataGear","version":"https://jsonfeed.org/version/1.1"}