Back to blog

// OSSeva Blog

Security

Apache HBase Vulnerabilities by Version: CVEs for HBase 1.7, 2.x and 3.0

Matt Reynolds7 min read

The short answer

The HBase project maintains three lines: 2.5 and 2.6, whose latest releases are 2.5.16 and 2.6.7 from 1 October 2026, and 3.0, which shipped 3.0.0 on 5 August 2026. Every older line is end of maintenance. The one HBase CVE published in 2026, CVE-2026-49326, lets a user of the Thrift or REST gateway read rows from a scanner another user opened. It is fixed in 2.5.15, 2.6.6 and 3.0.0-beta-2, and the advisory's range runs through every 2.4 release with no fix on that line.

HBase has published few CVEs of its own: NVD has five records that name Apache HBase, the oldest from 2013. On the older lines the larger exposure is often what HBase ships with: 1.7.2 and 2.2.7 build against ZooKeeper 3.4.10, and 2.3.7 against 3.5.7, both from ZooKeeper lines that no longer get fixes.

HBase release lines and their CVEs

Release dates are from the HBase downloads page and the Apache release announcements. End-of-maintenance dates are from the release manager table in the HBase Reference Guide. Each row lists the HBase CVEs whose ranges include the line and that have no fix in its latest release.

LineUpstream statusLatest releaseCVEs with no fix on this lineUpstream fix on this line
3.0Maintained; first GA release 5 August 20263.0.0, 5 August 2026None3.0.0-beta-2 and 3.0.0 carry the CVE-2026-49326 fix
2.6Maintained2.6.7, 1 October 2026None2.6.6, June 2026, for CVE-2026-49326
2.5Maintained; the stable release on the downloads page2.5.16, 1 October 2026None2.5.15, June 2026, for CVE-2026-49326
2.4End of maintenance; the reference guide gives June 20242.4.18, 25 May 2024, the final 2.4 releaseCVE-2026-49326No upstream fix on this line
2.3End of maintenance, October 20212.3.7CVE-2026-49326, whose range has no lower boundNo upstream fix on this line
2.2End of maintenance, April 20212.2.7CVE-2026-49326No upstream fix on this line
1.7End of maintenance, August 2022; the last 1.x line1.7.2CVE-2026-49326No upstream fix on this line; it already has the CVE-2018-8025 fix
2.0 and 2.1End of maintenance, September 2019 and May 20202.0.6; 2.1.10CVE-2026-49326; CVE-2019-0212 before 2.0.5 and 2.1.42.0.5 and 2.1.4 for CVE-2019-0212; 2.0.1 for CVE-2018-8025

The advisory for CVE-2026-49326 gives its range as "through 2.4.*" and names the hbase-thrift artifact, so it does not exclude 1.7, 2.2 or 2.3, and no fix exists for any of them. For release dates on every line, see the Apache HBase end-of-life chart and HBase 2.4 end of life.

Notable HBase CVEs by release line

CVSS is NVD's own score where NVD has scored the record, otherwise the CVSS 3.1 score CISA-ADP added. The Apache advisory rates CVE-2026-49326 important. None of these CVEs is in CISA's Known Exploited Vulnerabilities catalogue.

CVEIssueCVSSAffectedFixed in
CVE-2018-8025A race in the optional Thrift 1 server over HTTP can apply one user's authenticated session to another user, or treat an unauthenticated caller as authenticated8.1 (NVD)Every 1.x and 2.x line at the time except 1.0.01.2.6.1, 1.3.2.1, 1.4.5, 2.0.1
CVE-2019-0212With Kerberos, HBase authorization and SPNEGO on the REST server, REST requests run with the REST server's permissions rather than the end user's7.5 (NVD)2.0.0 to 2.0.4; 2.1.0 to 2.1.32.0.5, 2.1.4
CVE-2015-1836HBase sets incorrect ACLs on its ZooKeeper coordination state, so clients can read or change it7.3 (NVD)0.98 before 0.98.12.1; 1.0 before 1.0.1.1; 1.1 before 1.1.0.10.98.12.1, 1.0.1.1, 1.1.0.1
CVE-2026-49326The Thrift and REST gateways do not check scanner ownership, so one user can fetch rows from, or close, a scanner another user opened6.5 (CISA-ADP)Through 2.4.x; 2.5.0 to 2.5.14; 2.6.0 to 2.6.5; 3.0.0-alpha-1 to 3.0.0-beta-12.5.15, 2.6.6, 3.0.0-beta-2

All four rows are about the edges of an HBase cluster rather than the region servers themselves. Three concern the Thrift and REST gateways, which turn many end users into requests made by one gateway process. CVE-2026-49326 matters only where a gateway serves more than one user, for example with hbase.thrift.support.proxyuser or hbase.rest.support.proxyuser turned on, because a scanner ID opened by one user can then be used by another. The fix shipped in 2.5.15 and 2.6.6 in June 2026, and the advisory followed on 24 July 2026, so a cluster that took those releases was covered before the CVE was public.

The bundled ZooKeeper is the other half of the picture. HBase 1.7.2 and 2.2.7 build against ZooKeeper 3.4.10, which is inside the range of CVE-2019-0201, an ACL disclosure scored 5.9 by NVD that exposes digest authentication hashes. 2.3.7 builds against 3.5.7 and 2.4.18 against 3.8.4, which sits inside the range of the ZooKeeper advisories published in September 2026. Where HBase manages its own ensemble, that bundled version is the ZooKeeper server in production.

What each line gets

HBase 2.5, 2.6 and 3.0

These are the maintained lines, and 2.5.16, 2.6.7 and 3.0.0 carry every fix above. The downloads page marks 2.5 as the stable release. 3.0 is a new major version, so moving to it is a planned upgrade rather than a patch.

HBase 2.4

2.4.18, from 25 May 2024, was the last 2.4 release, and the reference guide lists the line as end of maintenance from June 2024. It has no fix for CVE-2026-49326. A move to 2.5 or 2.6 is a minor upgrade that can be done as a rolling restart; see upgrading HBase 2.4 to 2.5 or 2.6.

HBase 2.2 and 2.3

Both lines ended in 2021 and have no fix for CVE-2026-49326. They also carry the older bundled ZooKeeper, 3.4.10 in 2.2.7 and 3.5.7 in 2.3.7. The reference guide keeps a separate Hadoop compatibility matrix for each line, so an HBase upgrade from here often brings a Hadoop upgrade with it.

HBase 1.7

1.7.2, from August 2022, closed out the 1.x series. It has the 2018 Thrift fix, but nothing from 2026, and it runs on ZooKeeper 3.4.10. Moving to 2.x is a major-version upgrade with its own section in the reference guide; for the options, see Apache HBase support options.

What to do on each line

  • 2.5, 2.6 and 3.0. Take 2.5.16, 2.6.7 or 3.0.0.
  • 2.4. Move to 2.5.16 or 2.6.7. Until then, stop the Thrift and REST gateways where nothing uses them, and where they serve several users, turn off proxy user support or run one gateway per user group.
  • 1.7, 2.2 and 2.3. Plan the upgrade together with the Hadoop and ZooKeeper versions underneath, or take patched builds from a supplier that backports fixes. Until then, apply the same gateway steps, keep the Thrift, REST and ZooKeeper ports off untrusted networks, and check which ZooKeeper version your ensemble actually runs.

HBase usually shares its cluster with HDFS and YARN, so check the Hadoop line too; see Apache Hadoop vulnerabilities by version.

Where OSSeva fits

OSSeva ships patched, signed builds of Apache HBase 1.7, 2.2, 2.3 and 2.4 with region data untouched and the bundled ZooKeeper patched in the same build, along with transitive dependency patching for Netty, Jetty, Jackson and log4j, delivered as Maven artifacts, Docker images and tarballs with VEX statements for scanner findings. OSSeva backports fixes of this class to the end-of-life release lines it patches. They are available now on the Patch, Assure and Operate tiers. Assure adds a master, region server and ZooKeeper quorum review, a Kerberos, ACL and coprocessor exposure audit, and an upgrade plan to 2.5, 2.6 or 3.0, and Operate adds 24/7 region, compaction and RPC latency monitoring with a 15-minute P1 response and a named senior HBase engineer. See Apache HBase support and HBase extended support.

Tags

Apache HBaseCVEHBase 2.4HBase 3.0End of Life

Ready to get your open source under control?

Talk to an OSSeva engineer about CVE coverage, compliance, and migration support for your stack.