As cited
Copy frozen at (site build).
vulnerabilities
CVE-2026-57866: Apache Impala: Secrets Exfiltration via SSRF
A server-side request forgery (SSRF) vulnerability in Apache Impala 4.4.0 through 4.5.1 allows authenticated users with execute permissions on the ai_generate_text() function to exfiltrate secrets from configured credential providers. The vulnerability requires knowledge of the secret's key and affects systems using Hadoop credential provider paths in core-site.xml.
Why it matters: Organizations running Impala 4.4.x or 4.5.x must audit who has ai_generate_text() permissions and patch to a fixed version to prevent credential exposure through SSRF.
- Source published
- First seen by Cybersecurity Tracker