๐Ÿ” CVE Alert

CVE-2026-54048

MEDIUM 5.3

Apache Impala: Avro Schema URL Server-Side Request Forgery

CVSS Score
5.3
EPSS Score
0.0%
EPSS Percentile
0th

Specifying tblproperties('avro.schema.url'=' http://...' ) or with a 'file:///' URI on a table in Impala 2.0.0 to 4.5.1 on all platforms allows an attacker to trigger a GET request to internal endpoints they may not have access to but that Impala does and the response my be exposed via parsing error messages. Users are recommended to upgrade to version 4.5.2, which fixes this issue.

CWE CWE-918
Vendor apache software foundation
Product apache impala
Published Sep 9, 2026
Last Updated Sep 10, 2026
Stay Ahead of the Next One

Get instant alerts for apache software foundation apache impala

Be the first to know when new medium vulnerabilities affecting apache software foundation apache impala are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Apache Software Foundation / Apache Impala
2.0.0 โ‰ค 4.5.1

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
lists.apache.org: https://lists.apache.org/thread/cn3q4s8yx924ndlm3gt04o6g4rfm980c openwall.com: http://www.openwall.com/lists/oss-security/2026/09/08/21

Credits

๐Ÿ” zhaokaifei ChinaTelecom