DataEase is an open source data visualization and analysis tool. Prior to 2.10.24, a bypass of the H2 zip protocol and file dropper fix allows an authenticated attacker to upload a zip archive disguised with a .ttf extension through FontManage.saveFile and then exploit it through the zip protocol to achieve remote code execution. This issue is fixed in version 2.10.24.
{
"cna_assigner": "GitHub_M",
"cwe_ids": [
"CWE-434"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/55xxx/CVE-2026-55633.json"
}{
"extracted_events": [
{
"introduced": "0"
},
{
"fixed": "2.10.24"
}
],
"source": [
"AFFECTED_FIELD",
"REFERENCES"
]
}
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-55633.json"
[
{
"deprecated": false,
"digest": {
"function_hash": "24582629531658189514712935448802209446",
"length": 584
},
"id": "CVE-2026-55633-3fc3b180",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/dataease/dataease/commit/265b31179f1427c059f739841f2e39aaa6d1b937",
"target": {
"file": "sdk/extensions/extensions-datasource/src/main/java/io/dataease/extensions/datasource/plugin/DataEaseDatasourcePlugin.java",
"function": "extractSafeDriverFileName"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"118537362082061445725152950291290354977",
"55449974314291166848202674100008626307",
"332037074233965590049920659471367742489",
"237906029082083034717874455684778874366",
"1213195971310375162198228960107141329",
"274283975058861667824087010615783435516",
"273361471533360919988765371823509585674",
"287943799828963240061220833329182561093",
"281132015202904925317871751132941757509",
"162503767046484440949465562426906033689",
"38914044479362249757074732711490199605",
"125905306798081549100494293568066237995",
"148964774049135915023486320165790436989",
"32244710859029331638269377182981496204",
"252981252618635436312408306471906806669",
"207068588340752603547271181526832531445",
"308816980346541742210624117922844642029",
"90155521196787838854360626988375153508",
"1213195971310375162198228960107141329",
"274283975058861667824087010615783435516",
"273361471533360919988765371823509585674",
"302812263524297473749764448368748398948",
"166780773859398550627915791543199093552",
"148225505306916338127936416133331472315",
"81168819309056031255152339157455558446",
"34355409044219522769982766828635798305",
"84468102180923702989535553335247971520",
"1531484472872348773618306715770659301",
"269357028237043438440351306456275694044",
"32427581363615943355102292891927243871",
"213697633222201524210308552358624309889",
"210989672506622709899419618795761185386",
"67413185691681777106705290756273983760",
"150665614392921879224173566310862098076",
"234765334455145214021791268928969255613",
"63185485811497836790742559272655643031",
"217948600239407242443288765719496677915",
"321652757560326334960124906920488850823",
"157824968809202693628094362233145211778",
"55962353259127211185647996804085380567",
"88285815426506008431388981126727160787",
"179870055435125295571858159600561419742",
"269248775199125575005633893696141799094",
"100097073393289149460488117359812250206",
"195104290317571381439286071345834125333",
"32646765094466823769300172889398175415",
"253305229966370701048527327673799566533",
"114756630416864196756310355817065750056",
"305474181457241626037697707818447752957",
"37867223013196980436088675716232568468",
"208461563217995846177590416666073156039",
"13589470896418766358579441154401364937",
"200050827781351420473902348462698076658",
"308547693309287597494504168694699766494",
"111341780157262411495459248450185787540"
],
"threshold": 0.9
},
"id": "CVE-2026-55633-4eed2bf0",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/dataease/dataease/commit/265b31179f1427c059f739841f2e39aaa6d1b937",
"target": {
"file": "sdk/extensions/extensions-datasource/src/main/java/io/dataease/extensions/datasource/plugin/DataEaseDatasourcePlugin.java"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "244233215273914117458446441631952138559",
"length": 255
},
"id": "CVE-2026-55633-5d5c5930",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/dataease/dataease/commit/8892a6945b0b7a329a156155270fae58afa895bc",
"target": {
"file": "core/core-backend/src/main/java/io/dataease/font/manage/FontManage.java",
"function": "delete"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "110532318672023542130070984861619925582",
"length": 1259
},
"id": "CVE-2026-55633-619b4f2b",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/dataease/dataease/commit/8892a6945b0b7a329a156155270fae58afa895bc",
"target": {
"file": "core/core-backend/src/main/java/io/dataease/font/manage/FontManage.java",
"function": "saveFile"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "223574337679743192267041831021511126912",
"length": 594
},
"id": "CVE-2026-55633-699af5c3",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/dataease/dataease/commit/265b31179f1427c059f739841f2e39aaa6d1b937",
"target": {
"file": "sdk/extensions/extensions-datasource/src/main/java/io/dataease/extensions/datasource/plugin/DataEaseDatasourcePlugin.java",
"function": "unloadPlugin"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"63159729901470746290636832661553375134",
"254977216913930496287965249616743101646",
"108393760933712085524019361615094154663",
"93159895124701603671994202556886434113",
"194643405299870811938125400673145403092",
"237562987073151532833588986845063241828",
"284674546177607229397683295881590585316",
"93312402125165903041919484256090564764",
"84796939952385348728294174970208176386",
"325929475112713340823352271172927019347",
"319438752948240298319782252874182265145",
"303857041069560874483884832150449532640",
"64107328558196836039315084867106064531",
"314266046386674264566683725051921724683",
"126293794730870951881842463561363556316",
"319770128164839963889652529837651538178",
"2187252367853771841366408788439057906",
"241966785648540725919756540218692638440",
"322347462758980149897007254705502284460",
"280415025413215721729155263325254886303",
"78574262110037086758399944937965597454",
"2685138546016725535967955298629049312",
"101767532219190243343308005619767494490",
"218936612606481723353482909796225676826",
"81911723586227577603253238037921130645",
"126340126962237487779690566616125131642",
"129593585901156141992934611210779813852",
"265712334956033978505678542816544646019",
"212525010383229476084849277988061519808",
"63327458639553807947383498329302576614",
"156641677648576620471917334304911043731",
"2344603587248918934372378637422257946",
"8187814050556705114116370661888263381",
"301253090954672984394583223585257816528",
"316891952157542929877604455638789522826",
"98808140357322518789595172348283739535",
"19367855476103740280580691361188943643",
"278105376289709436054898777519586569432",
"147133147016680477418817864818548911621",
"283924489427764317724310395169416143193",
"151753797279278870893917404496585813713",
"133409091021178258385160949281826715359",
"22302905449319542772865721804489943159",
"214230374094766644341249757429374730112",
"90547565012791624982162580342442302099",
"298415729604903282662075205240220450402",
"146279542286153212638730213007289857183",
"96223915531727605223996191801214234269",
"139259571595527651539574538238689584349",
"180131802963564949869479895534928224186",
"314814686438099284831046069602001713633",
"54592930225335029664957332385552176127",
"313066800682951810455367421214274071333",
"41822724773901750817045339881023665377",
"270127306289725748055042564561162633058",
"338573240930918413366190257047149140611",
"909909405323769675332084097946427570"
],
"threshold": 0.9
},
"id": "CVE-2026-55633-715eb1cf",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/dataease/dataease/commit/8892a6945b0b7a329a156155270fae58afa895bc",
"target": {
"file": "core/core-backend/src/main/java/io/dataease/font/manage/FontManage.java"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "212511868958027570421057111574534705469",
"length": 807
},
"id": "CVE-2026-55633-b5269ba7",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/dataease/dataease/commit/8892a6945b0b7a329a156155270fae58afa895bc",
"target": {
"file": "core/core-backend/src/main/java/io/dataease/font/manage/FontManage.java",
"function": "download"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "165340796830397437116069734472446366976",
"length": 1062
},
"id": "CVE-2026-55633-c3fe3c7f",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/dataease/dataease/commit/265b31179f1427c059f739841f2e39aaa6d1b937",
"target": {
"file": "sdk/extensions/extensions-datasource/src/main/java/io/dataease/extensions/datasource/plugin/DataEaseDatasourcePlugin.java",
"function": "loadDriver"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "316159376187064092988902337895079880942",
"length": 445
},
"id": "CVE-2026-55633-c6df24a0",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/dataease/dataease/commit/8892a6945b0b7a329a156155270fae58afa895bc",
"target": {
"file": "core/core-backend/src/main/java/io/dataease/font/manage/FontManage.java",
"function": "create"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "212395036784794400859677715686853402280",
"length": 500
},
"id": "CVE-2026-55633-e6c13077",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/dataease/dataease/commit/8892a6945b0b7a329a156155270fae58afa895bc",
"target": {
"file": "core/core-backend/src/main/java/io/dataease/font/manage/FontManage.java",
"function": "edit"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "106366627437486803623682346719276550126",
"length": 344
},
"id": "CVE-2026-55633-e7a7c463",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/dataease/dataease/commit/265b31179f1427c059f739841f2e39aaa6d1b937",
"target": {
"file": "sdk/extensions/extensions-datasource/src/main/java/io/dataease/extensions/datasource/plugin/DataEaseDatasourcePlugin.java",
"function": "resolveDriverFile"
}
}
]
"2026-08-12T16:41:20Z"