CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

CVE-2026-73334: Apache Parquet Hadoop: File-controlled KMS URL is forwarded to pluggable KmsClient that skips host validation

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 6705

As cited

Copy frozen at (site build).

vulnerabilities

CVE-2026-73334: Apache Parquet Hadoop: File-controlled KMS URL is forwarded to pluggable KmsClient that skips host validation

CVE-2026-73334 affects Apache Parquet Hadoop versions 1.12 through 1.18.0 in the parquet-hadoop package used for envelope encryption of Parquet files. A potential vulnerability exists where an optional Key Management Service (KMS) URL from a file is forwarded to a pluggable KmsClient implementation without proper host validation. This allows an attacker to redirect key material requests to a malicious server.

Why it matters: Organizations using Apache Parquet Hadoop for encrypted file storage should update to a patched version to prevent potential credential theft or key compromise through KMS URL redirection attacks.

VendorsOracle
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary