CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

CVE-2026-54048: Apache Impala: Avro Schema URL Server-Side Request Forgery

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 6775

As cited

Copy frozen at (site build).

vulnerabilities

CVE-2026-54048: Apache Impala: Avro Schema URL Server-Side Request Forgery

CVE-2026-54048 affects Apache Impala versions 2.0.0 through 4.5.1 across all platforms. An attacker can specify a malicious Avro schema URL in table properties to trigger server-side request forgery (SSRF), allowing the server to make requests to internal endpoints and potentially expose responses through error messages. This vulnerability enables attackers to access resources that Impala can reach but they cannot directly access.

Why it matters: Organizations running Impala 2.0.0 through 4.5.1 should prioritize patching, as unauthenticated attackers can exploit this SSRF to discover and access internal services and sensitive information.

Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary