CVE-2026-50124

Source
https://cve.org/CVERecord?id=CVE-2026-50124
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-50124.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-50124
Aliases
  • GHSA-cjmg-jqmc-xj5v
Published
2026-07-15T19:38:14.211Z
Modified
2026-08-12T16:25:36.478553Z
Severity
  • 7.1 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N CVSS Calculator
Summary
DataEase: Remote Code Execution (RCE) via Zip Protocol & File Dropper
Details

DataEase is an open source data visualization and analysis tool. Prior to 2.10.23, DataEase can be exploited by uploading payload.zip through the Excel upload API /datasource/upload, creating an H2 datasource that uses the zip: protocol, and executing an SQL dataset path where CalciteProvider.jdbcFetchResultField calls statement.executeQuery(), causing precompiled Java aliases in test.mv.db to execute arbitrary code. This issue is fixed in version 2.10.23.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/50xxx/CVE-2026-50124.json",
    "cna_assigner": "GitHub_M",
    "cwe_ids": [
        "CWE-434"
    ]
}
References

Affected packages

Git / github.com/dataease/dataease

Affected ranges

Type
GIT
Repo
https://github.com/dataease/dataease
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Fixed
Fixed
Database specific
Show details
{
    "source": [
        "AFFECTED_FIELD",
        "REFERENCES"
    ],
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "fixed": "2.10.23"
        }
    ]
}

Affected versions

v1.*
v1.0.0
v2.*
v2.10.0
v2.10.1
v2.10.10
v2.10.11
v2.10.12
v2.10.13
v2.10.14
v2.10.15
v2.10.16
v2.10.17
v2.10.18
v2.10.19
v2.10.2
v2.10.20
v2.10.21
v2.10.22
v2.10.3
v2.10.4
v2.10.5
v2.10.6
v2.10.7
v2.10.8
v2.10.9
v2.2.0
v2.3.0
v2.6.0

Database specific

vanir_signatures
[
    {
        "signature_type": "Line",
        "deprecated": false,
        "digest": {
            "line_hashes": [
                "250116265459272533714315111760279100497",
                "224207896294139515533023797990062610240",
                "339491553894147295170033189397120937698",
                "97142947938543604819636395956544387028",
                "173896725595572891638537826793823816142",
                "303049740976639133256417823974542026175",
                "330099799982123102696899084791159167379",
                "56023985824183247680632081820744534780",
                "4026933729354017644797829218108517791",
                "280704109511616484882051245954708036291",
                "26742340294435194993140089071014012877",
                "327180951493110430046413687467583442599",
                "174477614890696280445432975381728139478",
                "308723608037055089243552183597655546937",
                "183920010412626920216261108551792835631",
                "282323379096949031976824852719461218867",
                "207503370590663238455892514184508003983",
                "10684706001663307638683384979868856620",
                "23757338840592367074786271824445765928",
                "159955869154170500017973317732380197205",
                "299656320907695007202738142707018905878",
                "308574010274805378245061709407129644741",
                "251334285116504276451543897108392266401",
                "67362837996066895491036262167965060049",
                "131427123251763910502019681955658018229",
                "109825679114459642275762499036657001208",
                "275447678748831037873452098175424029630",
                "332966653843206034549212734393941721897",
                "182555373230883698353849669576054603052",
                "207123363338539122740852658675436027855",
                "209423872604640323796517590532156950795",
                "210125975152700908260123470711463265521",
                "100497111774994311558304480530200211621",
                "95972057962943276810025533639087768480",
                "339425334311735617077985271214558675249",
                "259935689419008264471390201524153195804",
                "8646201268447419633596816786740514501",
                "192745633756022063120772606619233800542"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2026-50124-06f6ee78",
        "target": {
            "file": "core/core-backend/src/main/java/io/dataease/datasource/type/Pg.java"
        },
        "source": "https://github.com/dataease/dataease/commit/304104d70e27a97f8909981f56209edc117dc285",
        "signature_version": "v1"
    },
    {
        "signature_type": "Line",
        "deprecated": false,
        "digest": {
            "line_hashes": [
                "250116265459272533714315111760279100497",
                "224207896294139515533023797990062610240",
                "339491553894147295170033189397120937698",
                "97142947938543604819636395956544387028",
                "173896725595572891638537826793823816142",
                "303049740976639133256417823974542026175",
                "330099799982123102696899084791159167379",
                "268722526992698925359325136236577230272",
                "78695942967482120259914065844976883316",
                "285950918733159219114778038821062331321",
                "195671539872271482306120054713179080224",
                "141082705537910957127455786163173042814",
                "73859778259755844706838001102572711939",
                "60847749036902645706505933681435634471",
                "142753397491949537603458407151317779693",
                "17796270326912814320433972194529134037",
                "287758189622682488166661249750981589107",
                "145780470762644530862201389126687497105",
                "90821133587924392331008856544579248432",
                "6948591839792533124328451962765653911",
                "149149596411626419257010052391339033376",
                "3682491180337774735492088248212711218",
                "252816880996605386753725805148835888482",
                "240385693060531806676436591225063806831",
                "24698036681073158821340885456279047097",
                "185112485707262239357671148479975611999",
                "67362837996066895491036262167965060049",
                "131427123251763910502019681955658018229",
                "109825679114459642275762499036657001208",
                "10953689819024142538250758807302846974",
                "7507456059099766670545003070165445724",
                "74790747623033065531454115257825169089",
                "207123363338539122740852658675436027855",
                "209423872604640323796517590532156950795",
                "210125975152700908260123470711463265521",
                "100497111774994311558304480530200211621",
                "95972057962943276810025533639087768480",
                "339425334311735617077985271214558675249",
                "259935689419008264471390201524153195804",
                "165678318105873973209945929372716856208"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2026-50124-0b9ed85a",
        "target": {
            "file": "core/core-backend/src/main/java/io/dataease/datasource/type/Mysql.java"
        },
        "source": "https://github.com/dataease/dataease/commit/304104d70e27a97f8909981f56209edc117dc285",
        "signature_version": "v1"
    },
    {
        "signature_type": "Function",
        "deprecated": false,
        "digest": {
            "length": 1518.0,
            "function_hash": "195521166917494390286785258841538789043"
        },
        "id": "CVE-2026-50124-1963633c",
        "target": {
            "function": "getJdbc",
            "file": "core/core-backend/src/main/java/io/dataease/datasource/type/Mysql.java"
        },
        "source": "https://github.com/dataease/dataease/commit/304104d70e27a97f8909981f56209edc117dc285",
        "signature_version": "v1"
    },
    {
        "signature_type": "Function",
        "deprecated": false,
        "digest": {
            "length": 1230.0,
            "function_hash": "15494222016253386476854231414808831177"
        },
        "id": "CVE-2026-50124-2c45f1b7",
        "target": {
            "function": "getJdbc",
            "file": "core/core-backend/src/main/java/io/dataease/datasource/type/Sqlserver.java"
        },
        "source": "https://github.com/dataease/dataease/commit/304104d70e27a97f8909981f56209edc117dc285",
        "signature_version": "v1"
    },
    {
        "signature_type": "Line",
        "deprecated": false,
        "digest": {
            "line_hashes": [
                "159471170881518589176512041870075844069",
                "339491553894147295170033189397120937698",
                "97142947938543604819636395956544387028",
                "101298929573642802071728888223570198032",
                "211158115149331556494079950685910576042",
                "1694211023586680298609290136978099376",
                "123027150147707713114580784304762161518",
                "131618422457423071419306676237509776451",
                "229788581484826015273395741184679278804",
                "161378754054433202554490075114729454960",
                "274502511431147680723841718071578941168",
                "183861766025924545624066492557597577295",
                "319585197298398512857765024845014598892",
                "298112220770250500095987880054148860191",
                "190515896219352511085871518911511713409",
                "312810866761520394669779848445754320194",
                "66356444301563981300017945971200785178",
                "335412656131485878441236384713550420686",
                "128789957289550124868612299009705535605",
                "204433914157597240503199873817420693623",
                "234058510221909481901057874009146179132",
                "112288279939791228851549722120952068328",
                "96666174261160503130945884895016098725",
                "77280016341097313359542057327904403160",
                "285278964104609273825677640132337953824",
                "133628909163421834641951600554902670821",
                "49705660588032014071884621681836796323",
                "68233504285946658082638931608295824211",
                "173556416272382442763950552342125097953",
                "146053088157357147270629623262731951857",
                "155036222050612324691219448235116674465",
                "297316363989668859084891582423538725691",
                "130191747495566765357858499324510657492",
                "102274621447865676376022586434477777126",
                "255662639631320984342661882622926733368",
                "290098718112349591995885000545834972571",
                "160754126511524052666270806334617992201",
                "275321841767111314293762003185079205694",
                "245838964989395765674569667992022710600",
                "90531020164575833337180757157667131791",
                "12724382088439101302543677401660640091"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2026-50124-31349785",
        "target": {
            "file": "core/core-backend/src/main/java/io/dataease/datasource/type/Oracle.java"
        },
        "source": "https://github.com/dataease/dataease/commit/304104d70e27a97f8909981f56209edc117dc285",
        "signature_version": "v1"
    },
    {
        "signature_type": "Function",
        "deprecated": false,
        "digest": {
            "length": 1728.0,
            "function_hash": "322000652987343213249743682637488357388"
        },
        "id": "CVE-2026-50124-4749f4b8",
        "target": {
            "function": "getConnection",
            "file": "core/core-backend/src/main/java/io/dataease/datasource/provider/CalciteProvider.java"
        },
        "source": "https://github.com/dataease/dataease/commit/304104d70e27a97f8909981f56209edc117dc285",
        "signature_version": "v1"
    },
    {
        "signature_type": "Line",
        "deprecated": false,
        "digest": {
            "line_hashes": [
                "250116265459272533714315111760279100497",
                "224207896294139515533023797990062610240",
                "339491553894147295170033189397120937698",
                "97142947938543604819636395956544387028",
                "101298929573642802071728888223570198032",
                "211158115149331556494079950685910576042",
                "20409387090052583888599888847732403555",
                "37396709109749024597719450856925400805",
                "332369121711185247975002963469776728756",
                "306501916635380252692461002309842350771",
                "199393942858971458183282307423099287618",
                "197702988325276993985788520088684296265",
                "275142586625763177489719534886278723867",
                "195817921814386251975745830065707185382",
                "223471297459141520552184056178580297435",
                "272790013953672796150386807231842354032",
                "316790544829683262421920958366598592612",
                "45437300578907785385609087111929239441",
                "143023399493550275290993194879647302229",
                "185112485707262239357671148479975611999",
                "67362837996066895491036262167965060049",
                "131427123251763910502019681955658018229",
                "109825679114459642275762499036657001208",
                "10953689819024142538250758807302846974",
                "7507456059099766670545003070165445724",
                "74790747623033065531454115257825169089",
                "207123363338539122740852658675436027855",
                "122631873103082135781405329334762551440",
                "327581886155636108590998855266702706787",
                "69959730892188893067281689782473690309",
                "339655529324381547956859754344676935746",
                "326822035635552208311641298668560260135",
                "259935689419008264471390201524153195804",
                "165678318105873973209945929372716856208"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2026-50124-671660b6",
        "target": {
            "file": "core/core-backend/src/main/java/io/dataease/datasource/type/Mongo.java"
        },
        "source": "https://github.com/dataease/dataease/commit/304104d70e27a97f8909981f56209edc117dc285",
        "signature_version": "v1"
    },
    {
        "signature_type": "Line",
        "deprecated": false,
        "digest": {
            "line_hashes": [
                "250116265459272533714315111760279100497",
                "224207896294139515533023797990062610240",
                "339491553894147295170033189397120937698",
                "97142947938543604819636395956544387028",
                "173896725595572891638537826793823816142",
                "303049740976639133256417823974542026175",
                "330099799982123102696899084791159167379",
                "56023985824183247680632081820744534780",
                "4026933729354017644797829218108517791",
                "219214220776041794115080486185547689193",
                "202015769540809223843655617032594436612",
                "289209628330541251688631709633814954559",
                "121560307871414231742043775641037016824",
                "82836523950694103977919145236973816544",
                "153079355700782538909438556350567098521",
                "336942770476346027063339857753189685413",
                "159968911317974321178461876958610423918",
                "325410512187443166180113998938932294884",
                "38566212811177503331637519945295901851",
                "67362837996066895491036262167965060049",
                "131427123251763910502019681955658018229",
                "109825679114459642275762499036657001208",
                "233240062712779108443851347244426160586",
                "180800119835169587954399445912352354911",
                "281546187497072131402956443089960067621",
                "207123363338539122740852658675436027855",
                "209423872604640323796517590532156950795",
                "210125975152700908260123470711463265521",
                "100497111774994311558304480530200211621",
                "95972057962943276810025533639087768480",
                "339425334311735617077985271214558675249",
                "259935689419008264471390201524153195804",
                "195722710893138000717835567019889084310",
                "289647600227769662780912872424452196823"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2026-50124-68810f68",
        "target": {
            "file": "core/core-backend/src/main/java/io/dataease/datasource/type/Sqlserver.java"
        },
        "source": "https://github.com/dataease/dataease/commit/304104d70e27a97f8909981f56209edc117dc285",
        "signature_version": "v1"
    },
    {
        "signature_type": "Line",
        "deprecated": false,
        "digest": {
            "line_hashes": [
                "250116265459272533714315111760279100497",
                "224207896294139515533023797990062610240",
                "339491553894147295170033189397120937698",
                "97142947938543604819636395956544387028",
                "173896725595572891638537826793823816142",
                "303049740976639133256417823974542026175",
                "330099799982123102696899084791159167379",
                "56023985824183247680632081820744534780",
                "4026933729354017644797829218108517791",
                "85581480015319732989612933451271825315",
                "65038138489061431263874042230845772432",
                "325431696728402076451358792613292949856",
                "37519208458512841517164958142441893678",
                "339422692194014088315410905937406993337",
                "28774637479065912576392856413749524706",
                "216597736459683288341127446763871823551",
                "51835377143890183003176187750239556271",
                "41935422088733912849115379185214568329",
                "185071938514034374559760994541854064893",
                "219021135822343843840955335452681449881",
                "145780470762644530862201389126687497105",
                "90821133587924392331008856544579248432",
                "6948591839792533124328451962765653911",
                "149149596411626419257010052391339033376",
                "3682491180337774735492088248212711218",
                "72269916622576826156313085645714547124",
                "178144501166813955857708170895113653453",
                "241329092240254961187856855222418324480",
                "97881927660331271661822041524755775516",
                "67362837996066895491036262167965060049",
                "131427123251763910502019681955658018229",
                "109825679114459642275762499036657001208",
                "205084668740187907389131085646533115092",
                "202575528423228177279279601911254306662",
                "286133867867964277291206658611992444031",
                "207123363338539122740852658675436027855",
                "209423872604640323796517590532156950795",
                "210125975152700908260123470711463265521",
                "100497111774994311558304480530200211621",
                "95972057962943276810025533639087768480",
                "339425334311735617077985271214558675249",
                "259935689419008264471390201524153195804",
                "121489992750841342211549581341463543778",
                "256182230049869659918324725401497185784"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2026-50124-7c581599",
        "target": {
            "file": "core/core-backend/src/main/java/io/dataease/datasource/type/Impala.java"
        },
        "source": "https://github.com/dataease/dataease/commit/304104d70e27a97f8909981f56209edc117dc285",
        "signature_version": "v1"
    },
    {
        "signature_type": "Function",
        "deprecated": false,
        "digest": {
            "length": 1779.0,
            "function_hash": "108002283980576870767945656377025655667"
        },
        "id": "CVE-2026-50124-7eeb7ab0",
        "target": {
            "function": "getJdbc",
            "file": "core/core-backend/src/main/java/io/dataease/datasource/type/Pg.java"
        },
        "source": "https://github.com/dataease/dataease/commit/304104d70e27a97f8909981f56209edc117dc285",
        "signature_version": "v1"
    },
    {
        "signature_type": "Line",
        "deprecated": false,
        "digest": {
            "line_hashes": [
                "250116265459272533714315111760279100497",
                "224207896294139515533023797990062610240",
                "339491553894147295170033189397120937698",
                "97142947938543604819636395956544387028",
                "101298929573642802071728888223570198032",
                "211158115149331556494079950685910576042",
                "20409387090052583888599888847732403555",
                "319398436967168735628337714134653730339",
                "274336000952531682718871445582059004936",
                "226206026037102308028627587933519385431",
                "250607821624320240021707600059182626213",
                "201039484341792970810049140292130611720",
                "178860061441977632653490636502492984997",
                "47420976012989823752363797316411481465",
                "44878215910671932343013390040061774621",
                "232828246389259861167647341533125772484",
                "255648950396846088021994111297643037875",
                "198701130925416132219928984077806050136",
                "135788861313573537862620002636633174970",
                "252485070647857466151356133292115535959",
                "275719072317085315532351123451166127708",
                "229173076052871777603963911657901236890",
                "288346777830538320886490723928729032229",
                "110933217615169316001806491425634383769",
                "119436569636639328235914670588651979744",
                "340267665737122358492135763440263345986",
                "188380543299094146786110806957190941299",
                "182803503840484117842502312890803315974",
                "67362837996066895491036262167965060049",
                "198429882089509561822462810526667083558",
                "208700546527315116102477475516405352630",
                "275732732202983643545254665430581279164",
                "307766591075003097896027817968589240304",
                "127252074108955610374463560601827073414",
                "207123363338539122740852658675436027855",
                "48561236694434528196990371875733170886",
                "261405661639818930700983444253730556670",
                "280547399847225556066763418361261846428",
                "67508245266982376806399218296004350249",
                "72165126525473171270712977498410243268",
                "267925214973108380156070610123931479246",
                "221128677140524340466227054187331878455"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2026-50124-7f2f654e",
        "target": {
            "file": "core/core-backend/src/main/java/io/dataease/datasource/type/Db2.java"
        },
        "source": "https://github.com/dataease/dataease/commit/304104d70e27a97f8909981f56209edc117dc285",
        "signature_version": "v1"
    },
    {
        "signature_type": "Function",
        "deprecated": false,
        "digest": {
            "length": 912.0,
            "function_hash": "289119714468976722347678794913151859417"
        },
        "id": "CVE-2026-50124-806a8fa8",
        "target": {
            "function": "getJdbc",
            "file": "core/core-backend/src/main/java/io/dataease/datasource/type/Redshift.java"
        },
        "source": "https://github.com/dataease/dataease/commit/304104d70e27a97f8909981f56209edc117dc285",
        "signature_version": "v1"
    },
    {
        "signature_type": "Line",
        "deprecated": false,
        "digest": {
            "line_hashes": [
                "224833672634180117724202312331115355915",
                "306909744664174954452267539627811011772",
                "335468789831366810945521677509403052104",
                "243638940451132189078694226631787653275",
                "124203375016600617204113817910226646796",
                "235663144785239792757501736631225241845",
                "262992447574825667060866777096297627911",
                "202944191352503387674048537245907578598",
                "100363154664302364759893452949073751369",
                "193455797143702192650347914608268498041",
                "327260951182193794170955527355744314626",
                "265150325855804572422358658119638289038",
                "150894771664775069976516941241877966391",
                "196107015747605047649630231822692406542",
                "33822405332357892061514729931258993415",
                "74539085751953803493304597096851132044",
                "60191074662602098605901800186396117500",
                "302702044297443936743361422998120922441",
                "311820494019135473111110711125227726233",
                "202304759960513029034208000166614568375",
                "203203809835970131052024402072023033977",
                "191897933567213351103678574413929086466",
                "58917392583262570601160200514860542688",
                "201710857363908394338324974565852372940",
                "122979702893255794580075171226107102651",
                "427773989229280179654515784291238104",
                "218648589838076514242063037071920912426",
                "33586548429626358187455803685180312028",
                "118567063471201275206208340927753451149",
                "252022893856466835885683178538336664691",
                "48244891644916454308106627371876539367",
                "107682180280064594597720224283008109994",
                "31181098456736740308754102985944991664",
                "252815776606215735484246217773476179246",
                "210313881718194694313317714344055269518",
                "79658664778234474888756645955060350122",
                "286399653229628342167742210422561582656",
                "293598166944521394040419247077596577472",
                "179751636636569740158735828914256162479",
                "112295119801939248992292276160387565415",
                "262164974562944687415573552198169834382",
                "182476065514164777206927623526667440827",
                "3536361100068097405731460364459377555",
                "167429650334798714148453128075676068019",
                "323138129599398970767944330072309342652",
                "338863545573375729587382902158680854193",
                "31003290034195199626613182778261667816",
                "50029591626897561140144514600825745151",
                "240506079673750528661126567656552427066",
                "137457689763841209694626448126943377780",
                "253955915535024212308142255094435415403",
                "82996387360454490775792691097570046823",
                "229299819241486015586515111743354058493",
                "187593172777712436301374942791401670199",
                "134285415593828822587171933493660505696",
                "85354559799957776060984649975948676383",
                "251796089734907453996540136338814427618",
                "27313948244611412610367304690412682935",
                "65079804415619152571854558182186664056"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2026-50124-9401c60f",
        "target": {
            "file": "core/core-backend/src/main/java/io/dataease/datasource/provider/CalciteProvider.java"
        },
        "source": "https://github.com/dataease/dataease/commit/304104d70e27a97f8909981f56209edc117dc285",
        "signature_version": "v1"
    },
    {
        "signature_type": "Line",
        "deprecated": false,
        "digest": {
            "line_hashes": [
                "250116265459272533714315111760279100497",
                "224207896294139515533023797990062610240",
                "261419710062561994000747410248602327184",
                "111372501219840282388420949509201147010",
                "98110098685754662481036710274995963171",
                "260201256653774525109890304339868977693",
                "311574623271686424089517719026262964801",
                "140014944858385385643108693834864437956",
                "200425713958974817461298242118388924836",
                "311028703954222983691002607436566762574",
                "262153038871642495330980236635519347642",
                "168983286819799346024045419265186426493",
                "24325828987644189780635699805879625565",
                "325680708480320352097472740845871643775",
                "266442974166799542891684687613280505997",
                "82645390518281321564175766442723436565",
                "209325561196815138621248644011841943138",
                "214743281762040189895962888916943891653",
                "252003740299914611589266463641441740463",
                "205213316609403058939023130058083972857",
                "71311095195704801343117240489870195970",
                "154892139985415533106248647556400483505",
                "297682556955055740101545602197168346251",
                "23925642105770319601813755618378074179",
                "45624250010391124638196506952684033116",
                "267500290158921073160972209490651471117",
                "262548837049423633159435461093513008086",
                "166324582617736651266842542606443444295",
                "252675358983973635382164016606888294160",
                "218880904903455374501017517884828105907",
                "126602787994255635768618131473898263326",
                "215645654431958123846780285600258310093",
                "108587633537507210242609878158511307392"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2026-50124-a36cf7a1",
        "target": {
            "file": "core/core-backend/src/main/java/io/dataease/datasource/type/CK.java"
        },
        "source": "https://github.com/dataease/dataease/commit/304104d70e27a97f8909981f56209edc117dc285",
        "signature_version": "v1"
    },
    {
        "signature_type": "Line",
        "deprecated": false,
        "digest": {
            "line_hashes": [
                "126067640218728191648259567113334300090",
                "235415529303935695462415900794708277276",
                "185185851955305490407913402745703468538",
                "140836386882064611352654354477465841455",
                "190058830234638160642624468214813575610"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2026-50124-a8f0aabf",
        "target": {
            "file": "core/core-backend/src/main/java/io/dataease/datasource/server/DatasourceServer.java"
        },
        "source": "https://github.com/dataease/dataease/commit/a7bffa795cb0ca041dce0effe68479cf3bf13db1",
        "signature_version": "v1"
    },
    {
        "signature_type": "Function",
        "deprecated": false,
        "digest": {
            "length": 1960.0,
            "function_hash": "155392025069983958923437687010018964527"
        },
        "id": "CVE-2026-50124-b45dded6",
        "target": {
            "function": "uploadFile",
            "file": "core/core-backend/src/main/java/io/dataease/datasource/server/DatasourceServer.java"
        },
        "source": "https://github.com/dataease/dataease/commit/a7bffa795cb0ca041dce0effe68479cf3bf13db1",
        "signature_version": "v1"
    },
    {
        "signature_type": "Line",
        "deprecated": false,
        "digest": {
            "line_hashes": [
                "250116265459272533714315111760279100497",
                "224207896294139515533023797990062610240",
                "203957935382934669947951522629744769219",
                "211158115149331556494079950685910576042",
                "243174594131808409328054137659796687740",
                "64409738125818515307025222518115649605",
                "335604061887272429204467943407576993161",
                "314676392783251565623302822662462651724",
                "119113839734709816557337376332353761183",
                "127446740025619118387596300107818454577",
                "214986878168920748598933374721188014414",
                "137278526080479958961014853542496482301",
                "8076710213396104737491785370767937964",
                "117720712834970546490761738245715521022",
                "223118877555511687709919707996133164853",
                "91742545273906516284889946656264272625",
                "122433282545080507374601910182537973772",
                "82036269544697145675146748477221738947",
                "163049768825189679937974761630613090860",
                "280752800271166071417104618808669309818",
                "226048810142663792191699428591511417159",
                "88923033799386998949852161864356832130",
                "324478029129289841044131770767825528833"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2026-50124-c15d90b5",
        "target": {
            "file": "core/core-backend/src/main/java/io/dataease/datasource/type/H2.java"
        },
        "source": "https://github.com/dataease/dataease/commit/304104d70e27a97f8909981f56209edc117dc285",
        "signature_version": "v1"
    },
    {
        "signature_type": "Function",
        "deprecated": false,
        "digest": {
            "length": 74.0,
            "function_hash": "339043373435950272243109152425841996209"
        },
        "id": "CVE-2026-50124-d13e7a4f",
        "target": {
            "function": "getH2IllegalParameters",
            "file": "core/core-backend/src/main/java/io/dataease/datasource/type/H2.java"
        },
        "source": "https://github.com/dataease/dataease/commit/304104d70e27a97f8909981f56209edc117dc285",
        "signature_version": "v1"
    },
    {
        "signature_type": "Function",
        "deprecated": false,
        "digest": {
            "length": 387.0,
            "function_hash": "317027902876756346962253485668718863143"
        },
        "id": "CVE-2026-50124-d3d94baa",
        "target": {
            "function": "getJdbc",
            "file": "core/core-backend/src/main/java/io/dataease/datasource/type/H2.java"
        },
        "source": "https://github.com/dataease/dataease/commit/304104d70e27a97f8909981f56209edc117dc285",
        "signature_version": "v1"
    },
    {
        "signature_type": "Function",
        "deprecated": false,
        "digest": {
            "length": 1650.0,
            "function_hash": "131683431772542749408047844190145900213"
        },
        "id": "CVE-2026-50124-d655b546",
        "target": {
            "function": "getJdbc",
            "file": "core/core-backend/src/main/java/io/dataease/datasource/type/Db2.java"
        },
        "source": "https://github.com/dataease/dataease/commit/304104d70e27a97f8909981f56209edc117dc285",
        "signature_version": "v1"
    },
    {
        "signature_type": "Function",
        "deprecated": false,
        "digest": {
            "length": 1052.0,
            "function_hash": "71082679955952813364871408220133034826"
        },
        "id": "CVE-2026-50124-ec482249",
        "target": {
            "function": "getJdbc",
            "file": "core/core-backend/src/main/java/io/dataease/datasource/type/Mongo.java"
        },
        "source": "https://github.com/dataease/dataease/commit/304104d70e27a97f8909981f56209edc117dc285",
        "signature_version": "v1"
    },
    {
        "signature_type": "Function",
        "deprecated": false,
        "digest": {
            "length": 288.0,
            "function_hash": "312105606868322232928354545122477168360"
        },
        "id": "CVE-2026-50124-f68afdcf",
        "target": {
            "function": "getOracleIllegalParameters",
            "file": "core/core-backend/src/main/java/io/dataease/datasource/type/Oracle.java"
        },
        "source": "https://github.com/dataease/dataease/commit/304104d70e27a97f8909981f56209edc117dc285",
        "signature_version": "v1"
    },
    {
        "signature_type": "Function",
        "deprecated": false,
        "digest": {
            "length": 1029.0,
            "function_hash": "280129360455038217086155120199129454859"
        },
        "id": "CVE-2026-50124-f68da0ae",
        "target": {
            "function": "getJdbc",
            "file": "core/core-backend/src/main/java/io/dataease/datasource/type/Oracle.java"
        },
        "source": "https://github.com/dataease/dataease/commit/304104d70e27a97f8909981f56209edc117dc285",
        "signature_version": "v1"
    },
    {
        "signature_type": "Function",
        "deprecated": false,
        "digest": {
            "length": 1482.0,
            "function_hash": "200743905014469396433403405247431173752"
        },
        "id": "CVE-2026-50124-f6a28bb9",
        "target": {
            "function": "getJdbc",
            "file": "core/core-backend/src/main/java/io/dataease/datasource/type/CK.java"
        },
        "source": "https://github.com/dataease/dataease/commit/304104d70e27a97f8909981f56209edc117dc285",
        "signature_version": "v1"
    },
    {
        "signature_type": "Line",
        "deprecated": false,
        "digest": {
            "line_hashes": [
                "250116265459272533714315111760279100497",
                "224207896294139515533023797990062610240",
                "339491553894147295170033189397120937698",
                "97142947938543604819636395956544387028",
                "173896725595572891638537826793823816142",
                "303049740976639133256417823974542026175",
                "330099799982123102696899084791159167379",
                "32439733472675052189849000959639281953",
                "167592803783411658259748052805776901671",
                "279722978440801233934751627403094201073",
                "277734259416141070615171845274824281433",
                "34925496864985073391777061603925867816",
                "216962888895229561523906007936811682323",
                "197609987962733016545062199879861464352",
                "317143147435927274322284371066829771593",
                "142844085740466861434925555970368097304",
                "329936594754537464502735973331385761454",
                "257478952777562646373608135196173604062",
                "241208805802270033807141699228111387907",
                "12306237695029834555896646522004477397",
                "282323379096949031976824852719461218867",
                "207503370590663238455892514184508003983",
                "10684706001663307638683384979868856620",
                "23757338840592367074786271824445765928",
                "20790081667826097320660812204742494093",
                "220047257905645931272734746335399292370",
                "172661102953674294830285964541596889401",
                "166759300066961917014932902680801064439",
                "67362837996066895491036262167965060049",
                "121792339078831036714911070597933511577",
                "44855027470365116975801555806744481214",
                "200593759166240090927129667529105718476",
                "64476868810085766647794715073269890612",
                "190315504713277108788318342843706490835",
                "153029330650419253427759949809051101520",
                "324708778598576031769841395566715551124",
                "95838934449568711986437823037153057331",
                "86824683205976319609637127934163987207",
                "339425334311735617077985271214558675249",
                "259935689419008264471390201524153195804",
                "8646201268447419633596816786740514501",
                "192745633756022063120772606619233800542"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2026-50124-f6bdd357",
        "target": {
            "file": "core/core-backend/src/main/java/io/dataease/datasource/type/Redshift.java"
        },
        "source": "https://github.com/dataease/dataease/commit/304104d70e27a97f8909981f56209edc117dc285",
        "signature_version": "v1"
    },
    {
        "signature_type": "Function",
        "deprecated": false,
        "digest": {
            "length": 1521.0,
            "function_hash": "46522080299237582001630540585941785618"
        },
        "id": "CVE-2026-50124-fdd238f2",
        "target": {
            "function": "getJdbc",
            "file": "core/core-backend/src/main/java/io/dataease/datasource/type/Impala.java"
        },
        "source": "https://github.com/dataease/dataease/commit/304104d70e27a97f8909981f56209edc117dc285",
        "signature_version": "v1"
    },
    {
        "signature_type": "Function",
        "deprecated": false,
        "digest": {
            "length": 262.0,
            "function_hash": "104362715885357395157132767058994149283"
        },
        "id": "CVE-2026-50124-ff29115b",
        "target": {
            "function": "checkIllegalParameters",
            "file": "core/core-backend/src/main/java/io/dataease/datasource/type/CK.java"
        },
        "source": "https://github.com/dataease/dataease/commit/304104d70e27a97f8909981f56209edc117dc285",
        "signature_version": "v1"
    }
]
source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-50124.json"
vanir_signatures_modified
"2026-08-12T16:25:36Z"