As cited
Copy frozen at (site build).
vulnerabilities
CVE-2026-73334: Apache Parquet Hadoop: File-controlled KMS URL is forwarded to pluggable KmsClient that skips host validation
CVE-2026-73334 affects Apache Parquet Hadoop versions 1.12 through 1.18.0 in the parquet-hadoop package used for envelope encryption of Parquet files. A potential vulnerability exists where an optional Key Management Service (KMS) URL from a file is forwarded to a pluggable KmsClient implementation without proper host validation. This allows an attacker to redirect key material requests to a malicious server.
Why it matters: Organizations using Apache Parquet Hadoop for encrypted file storage should update to a patched version to prevent potential credential theft or key compromise through KMS URL redirection attacks.
- Source published
- First seen by Cybersecurity Tracker