Server-side Request Forgery (SSRF) Affecting org.apache.hive:hive-common package, versions [,4.2.1)


Severity

Recommended
0.0
medium
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.44% (37th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-JAVA-ORGAPACHEHIVE-19256917
  • published25 Aug 2026
  • disclosed25 Aug 2026
  • creditzhaokaifei

Introduced: 25 Aug 2026

NewCVE-2026-55976  (opens in a new tab)
CWE-918  (opens in a new tab)

How to fix?

Upgrade org.apache.hive:hive-common to version 4.2.1 or higher.

Overview

org.apache.hive:hive-common is a reading, writing, and managing large datasets residing in distributed storage using SQL.

Affected versions of this package are vulnerable to Server-side Request Forgery (SSRF) via Avro SerDe schema resolution in AvroSerdeUtils.determineSchemaOrThrowException and the Avro table authorization paths in AuthorizationUtils, CommandAuthorizerV2, CreateTableEvent, and AlterTableEvent. An authenticated attacker with CREATE TABLE privilege can cause the Hive server to fetch an attacker-controlled avro.schema.url by creating or altering an Avro table and then getting it queried. This can expose cloud metadata endpoints, internal network services, or local server files to the Hive process identity, and the affected query or table operation can be used to trigger the outbound fetch.

CVSS Base Scores

version 4.0
version 3.1