Input validation error in Apache Hive - CVE-2026-55976

 

Input validation error in Apache Hive - CVE-2026-55976

Published: August 27, 2026


Vulnerability identifier: #VU145881
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-55976
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to cause the Hive server to fetch an attacker-controlled URL and disclose sensitive information.

The vulnerability exists due to insufficient input validation in Hive Avro SerDe schema resolution when resolving the avro.schema.url table property on an Avro table that is subsequently queried. A remote user can create a crafted Avro table with a malicious avro.schema.url value to cause the Hive server to fetch an attacker-controlled URL and disclose sensitive information.

Exploitation requires the ability to create a table, and external tables are typically required in practice.


Affected software

Apache Hive
IBM SPSS Modeler

How to mitigate CVE-2026-55976

Install security update from vendor's website.

Apache Hive - update to 4.2.1

External References

Related Security Bulletins