As cited
Copy frozen at (site build).
vulnerabilities
CVE-2026-54048: Apache Impala: Avro Schema URL Server-Side Request Forgery
CVE-2026-54048 affects Apache Impala versions 2.0.0 through 4.5.1 across all platforms. An attacker can specify a malicious Avro schema URL in table properties to trigger server-side request forgery (SSRF), allowing the server to make requests to internal endpoints and potentially expose responses through error messages. This vulnerability enables attackers to access resources that Impala can reach but they cannot directly access.
Why it matters: Organizations running Impala 2.0.0 through 4.5.1 should prioritize patching, as unauthenticated attackers can exploit this SSRF to discover and access internal services and sensitive information.
- Source published
- First seen by Cybersecurity Tracker