Server-Side Request Forgery in Apache Hive Affects Multiple Versions
CVE-2026-55976

Currently unrated

Key Information:

Vendor

Apache

Vendor
CVE Published:
25 August 2026

What is CVE-2026-55976?

A Server-Side Request Forgery (SSRF) vulnerability in Apache Hive prior to version 4.2.1 allows an authenticated remote attacker, equipped with the CREATE TABLE privilege, to manipulate the avro.schema.url table property of an Avro table. This misconfiguration can result in the Hive server fetching URLs controlled by the attacker. Such an exploit can expose sensitive data including cloud instance metadata and internal network service details. Administrators are urged to inspect Hive metadata for suspicious URLs and enforce prompt upgrades to the patched version to safeguard against potential exploits.

Affected Version(s)

Apache Hive 2.1.0 <= 4.2.0

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

zhaokaifei
.