Server-Side Request Forgery in Apache Hive Affects Multiple Versions
CVE-2026-55976
Currently unrated
What is CVE-2026-55976?
A Server-Side Request Forgery (SSRF) vulnerability in Apache Hive prior to version 4.2.1 allows an authenticated remote attacker, equipped with the CREATE TABLE privilege, to manipulate the avro.schema.url table property of an Avro table. This misconfiguration can result in the Hive server fetching URLs controlled by the attacker. Such an exploit can expose sensitive data including cloud instance metadata and internal network service details. Administrators are urged to inspect Hive metadata for suspicious URLs and enforce prompt upgrades to the patched version to safeguard against potential exploits.
Affected Version(s)
Apache Hive 2.1.0 <= 4.2.0