ZeroHour
Product

Apache Impala

0 mentions in 7 days · 4 in 30 days · 4 total · first seen · last

Timeline

CVE-2026-65181: Apache Impala: RCE via External Data Source Class Loading

Apache Impala CVE-2026-65181 allows remote code execution through class loading of external data sources; rated important by Apache.

Apache disclosed CVE-2026-65181, a remote code execution vulnerability in Apache Impala triggered via class loading of external data sources. The Apache Software Foundation rated the issue 'important'. The disclosure was posted to the oss-security mailing list on September 8, 2026.

CVE-2026-57866: Apache Impala: Secrets Exfiltration via SSRF

Apache Impala CVE-2026-57866 lets authenticated users abuse ai_generate_text() to exfiltrate secrets from configured Hadoop credential providers via SSRF.

A server-side request forgery affects Apache Impala versions 4.4.0 through 4.5.1. Authenticated users with permission to execute the ai_generate_text() function can exfiltrate secrets provided by credential providers configured via hadoop.security.credential.provider.path in core-site.xml. The attacker must know the secret's key name, and Apache rates the issue 'important'.

CVE-2026-56207: Apache Impala: SAML authentication bypass via forged bearer token

Apache Impala CVE-2026-56207 allows forged SAML bearer tokens on the hs2-http interface, letting attackers impersonate other users; fixed in 4.5.2.

Apache Impala versions 4.0.0 through 4.5.1 fail to verify the bearer token signature in the final step of SAML2 authentication for the hs2-http interface. An attacker can alter the username and act as another user. Users are recommended to upgrade to version 4.5.2, and Apache rated the issue critical. It was reported by Andrew Rukin of Arenadata.

CVE-2026-54048: Apache Impala: Avro Schema URL Server-Side Request Forgery

Apache Impala CVE-2026-54048 lets crafted Avro schema URLs trigger SSRF to internal endpoints, with responses potentially leaking via error messages.

A server-side request forgery in Apache Impala 2.0.0 through 4.5.1 on all platforms can be triggered via an Avro schema URL using an http or file:/// URI on a table. An attacker can cause Impala to send GET requests to internal endpoints it can access, and responses may be exposed through parsing error messages. Users are advised to upgrade to a fixed release.

oss-security · 7d agoVulnerabilityCVE-2026-540481

Related CVEs

  • SAML2 authentication bypass in Apache Impala hs2-http via unverified bearer token
    Apache Impala's final step of SAML2 authentication on its hs2-http interface accepts a Bearer token without verifying its cryptographic signature (CWE-347). An attacker with network access to the hs2-http endpoint can submit a forged bearer token with an altered user name, and Impala will accept it as valid. This lets the attacker impersonate another user and act as that user within Impala, bypassing the SAML2 authentication control. All Apache Impala releases from version 4.0.0 onward are affected when SAML2 authentication is used with the hs2-http interface; the issue is fixed in version 4.5.2. No public proof-of-concept or in-the-wild exploitation is known, the flaw is not in CISA KEV, and CVSS has not yet been assigned.
    · Apache Impala >= 4.0.0 (fixed in 4.5.2)niche
  • SSRF in Apache Impala lets authenticated users exfiltrate credential-provider secrets
    Apache Impala versions 4.4.x and 4.5.x contain a server-side request forgery (CWE-918) in the ai_generate_text() SQL function. An authenticated Impala user with permission to execute ai_generate_text() can trigger server-side requests that exfiltrate secrets supplied by the credential providers configured in the hadoop.security.credential.provider.path property of core-site.xml, provided the user already knows the secret's key name. Successful exploitation lets an attacker read sensitive credentials held by the Impala service, such as storage or cloud keys, potentially enabling follow-on access to the systems those credentials protect. Only deployments running Impala 4.4.x or 4.5.x that have credential providers configured and permit users to call the affected function are exposed. There is no CVSS score yet, no known public proof-of-concept, and no evidence of exploitation in the wild; the issue is not on the CISA KEV list.
    · Apache Impala 4.4.x and 4.5.x
  • Authenticated RCE in Apache Impala via Data Source table class loading
    CVE-2026-65181 is an insufficient-authorization flaw (CWE-913) in how Apache Impala handles Data Source tables, affecting all Impala releases from 2.7 through 4.5. An authenticated client who holds the privileges to upload a file to remote storage and to create a table can register a Data Source table whose custom Java classes Impala then loads, causing the service to execute attacker-controlled Java code. Successful exploitation yields remote code execution with high impact on confidentiality and integrity (CVSS 3.1: 8.1; no availability impact scored). Any organization running Impala 2.7-4.5 where non-administrative users can write to backend storage and issue CREATE TABLE statements is affected, while clusters where these privileges are restricted to administrators are largely not exposed. There is no evidence of exploitation to date — the issue is not on CISA's KEV list and no public proof-of-concept is known — and the Apache security team recommends upgrading to 4.5.2.
    · Apache Impala 2.7 through 4.5 (all releases prior to 4.5.2; fixed in 4.5.2)moderate
  • Server-Side Request Forgery in Apache Impala via Avro Schema URL
    Apache Impala contains a server-side request forgery (CWE-918) in its handling of the Avro schema URL table property. An attacker who can create or alter a table can set tblproperties('avro.schema.url'='http://...') — or use a 'file:///' URI — causing Impala (versions 2.0.0 through 4.5.1, on all platforms) to issue a GET request to an internal endpoint that the attacker may not have direct access to but that Impala can reach. The attacker gains SSRF access to internal services reachable from Impala, and the response content may be disclosed back to the attacker through Avro schema parsing error messages. All users running affected Impala versions 2.0.0 to 4.5.1 are exposed, with risk concentrated in environments where users can define or modify table properties and Impala can reach internal endpoints such as management interfaces or cloud metadata services. There are no known public proof-of-concept exploits, no confirmed in-the-wild exploitation, and the issue is not listed in CISA's KEV; the flaw is fixed in Impala 4.5.2.
    · Apache Impala 2.0.0 to 4.5.1 (all platforms)moderate

Appears with

Entities are extracted by the model from each article. Watching an entity keeps it in this browser only (no account); the watchlist page and dashboard alerts use it.