Input validation error in Apache Hive - CVE-2026-55976
Published: August 27, 2026
Vulnerability details
The vulnerability allows a remote user to cause the Hive server to fetch an attacker-controlled URL and disclose sensitive information.
The vulnerability exists due to insufficient input validation in Hive Avro SerDe schema resolution when resolving the avro.schema.url table property on an Avro table that is subsequently queried. A remote user can create a crafted Avro table with a malicious avro.schema.url value to cause the Hive server to fetch an attacker-controlled URL and disclose sensitive information.
Exploitation requires the ability to create a table, and external tables are typically required in practice.
Affected software
IBM SPSS Modeler