Back to blog

// OSSeva Blog

Security

Apache Hive Vulnerabilities by Version: CVEs for Hive 1.2, 2.3, 3.1 and 4.x

Randall McClure8 min read

The short answer

Only one Hive release has every fix: 4.2.1, released on 24 August 2026. It fixes three CVEs published the next day. CVE-2026-53561 lets an unauthenticated attacker log in as any user on HiveServer2 in SAML mode, CVE-2026-49845 is an SQL injection in the metastore, and CVE-2026-55976 lets a user who can create tables make Hive fetch any URL. The Hive project voted end of life for 1.x on 11 April 2024, 2.x on 20 May 2024 and 3.x on 8 October 2024. It has published no support policy for 4.x minor lines, and neither 4.0 nor 4.1 has had a release since its successor shipped.

CVE-2026-55976 reaches back to 2.1.0, so Hive 2.3.10 and 3.1.3 carry it with no upstream fix. Those two lines also miss three fixes from 2024 that shipped only in Hive 4, and 4.2.1 needs JDK 21, so for most 2.x and 3.x estates the fix is a platform upgrade rather than a patch.

Hive release lines and their CVEs

Release and end-of-life dates are from the news on the Hive downloads page. Each row lists the CVEs from the Apache advisories for Hive whose ranges include the line and that have no fix in its latest release.

LineUpstream statusLatest releaseCVEs with no fix on this lineUpstream fix on this line
4.2Current; requires JDK 214.2.1, 24 August 2026None4.2.1 for the three 2026 CVEs; 4.2.0 for CVE-2025-62728
4.1Superseded by 4.2; no release since 4.1.04.1.0, 31 July 2025CVE-2026-55976, CVE-2026-53561, CVE-2026-49845, CVE-2025-62728No upstream fix on this line
4.0Superseded; no release since 4.0.14.0.1, 2 October 2024CVE-2026-55976, CVE-2026-53561, CVE-2026-498454.0.1 for CVE-2024-29869
3.1End of life, 8 October 20243.1.3, 8 April 2022CVE-2026-55976, CVE-2024-29869, CVE-2024-23953, CVE-2024-239453.1.3 for CVE-2021-34538; 3.1.1 for CVE-2018-11777
2.3End of life, 20 May 20242.3.10, 9 May 2024The 3.1 list plus CVE-2021-345382.3.8 for CVE-2020-1926; 2.3.4 for CVE-2018-11777; 2.3.3 for CVE-2018-1282
1.2End of life, 11 April 20241.2.2, 7 April 2017CVE-2024-29869, CVE-2024-23945, CVE-2021-34538, CVE-2020-1926, CVE-2018-11777, CVE-2018-1282No upstream fix on this line

The fix for CVE-2021-34538, HIVE-25468, went into 3.1.3 and 4.0.0 only, so Hive 2.3.10 never got it even though it shipped two years later. For release dates on every line, see the Apache Hive end-of-life chart and Hive 3 end of life.

Notable Hive CVEs by release line

CVSS is NVD's own score where NVD has scored the record, otherwise the CVSS 3.1 score CISA-ADP added. NVD has not scored any of the Hive CVEs published since 2024 itself. None of these CVEs is in CISA's Known Exploited Vulnerabilities catalogue.

CVEIssueCVSSAffectedFixed in
CVE-2026-49845Metastore RPCs build direct SQL from client-supplied partition names, so a crafted name can read, update or truncate partitions it should not reach9.8 (CISA-ADP)4.0.0 to 4.2.04.2.1
CVE-2018-1282Crafted arguments bypass the escaping the JDBC driver applies in PreparedStatement, an SQL injection on the client side9.1 (NVD)JDBC driver 0.7.1 to 2.3.22.3.3
CVE-2026-55976A user with CREATE TABLE sets avro.schema.url on an Avro table, and Hive fetches that URL when the table is queried, exposing cloud metadata, internal services or local files9.1 (CISA-ADP)2.1.0 to 4.2.04.2.1
CVE-2018-11777Local resources on HiveServer2 hosts are not protected when Ranger, Sentry or SQL standard authorization is not in use8.1 (NVD)All versions through 2.3.3 and 3.1.02.3.4, 3.1.1, with the fallback authorizer configured
CVE-2021-34538CREATE and DROP FUNCTION skip authorization, so an unprivileged user can repoint an existing UDF at a new, possibly malicious jar7.5 (NVD)Before 3.1.33.1.3, 4.0.0
CVE-2026-53561HiveServer2 in HTTP mode with SAML authentication accepts a forged bearer token, so an unauthenticated attacker gets a session as any user7.4 (CISA-ADP)4.0.0 to 4.2.04.2.1
CVE-2024-23953LLAP compares message signatures with a non-constant-time check, so an authorized user can forge a signature byte by byte6.5 (CISA-ADP)2.2.0 before 4.0.04.0.0
CVE-2024-23945The HiveServer2 CookieSigner returns the correct signature when a cookie fails verification5.9 (CISA-ADP)1.2.0 before 4.0.04.0.0
CVE-2024-29869Hive writes a credentials file to a temporary directory with permissions 644, readable by other local users5.5 (CISA-ADP)1.1.0 before 4.0.14.0.1
CVE-2025-62728SQL injection in the metastore's delete column statistics Thrift API, reachable only by callers allowed to use the Thrift API directly5.4 (CISA-ADP)4.1.0 before 4.2.04.2.0

The three 2026 CVEs each need a different setup. CVE-2026-53561 matters only where HiveServer2 runs in HTTP transport with hive.server2.authentication set to SAML, but there it needs no credentials at all, including when a proxy such as Apache Knox forwards unauthenticated requests. CVE-2026-49845 and CVE-2025-62728 are reached through the metastore's direct SQL path, which is on by default through metastore.try.direct.sql, and need a caller that can talk to the metastore. CVE-2026-55976 needs only an ordinary user with DDL rights, which is common in shared warehouses. Two other CVEs, CVE-2022-41137 in the metastore and CVE-2023-35701 in the JDBC driver, affected only the 4.0.0 alpha and beta builds and were fixed in 4.0.0.

Hive 1.2.2, 2.3.10 and 3.1.3 all build against ZooKeeper 3.4.6, which HiveServer2 uses for service discovery, high availability and locking. That release is inside the ranges of CVE-2018-8012, a quorum join without authentication scored 7.5 by NVD, and CVE-2019-0201, scored 5.9. Hive 4.0.1 builds against ZooKeeper 3.8.3 and 4.2.1 against 3.8.4, both inside the range of the ZooKeeper advisories published in September 2026.

What each line gets

Hive 4.2

4.2.1 carries every fix above. 4.2 made JDK 21 the minimum, so moving to it from 4.0 or 4.1 can mean a JDK change on every HiveServer2 and metastore host as well as a release upgrade.

Hive 4.0 and 4.1

Neither line has had a release since its successor shipped, and the project publishes no end date for either. Both miss the three August 2026 fixes, and 4.1.0 also misses the 4.2.0 fix for CVE-2025-62728. 4.0.0 users should at least take 4.0.1, which fixes CVE-2024-29869.

Hive 3.1

3.1.3, from April 2022, is the last 3.x release. It has the 2021 UDF authorization fix but none of the 2024 fixes, which shipped in 4.0.0 and 4.0.1, and none from 2026. Moving to Hive 4 means a metastore schema upgrade and new client drivers; see upgrading from Hive 3 to Hive 4.

Hive 2.3 and 1.2

2.3.10 has the 2018 and 2020 fixes but lacks CVE-2021-34538 as well as everything from 2024 and 2026. 1.2.2 has had no release since 2017, so it also lacks the JDBC driver fix for CVE-2018-1282 and the HiveServer2 local resource fix for CVE-2018-11777. The advisory's mitigation for CVE-2018-11777 relies on the fallback authorizer that 2.3.4 and 3.1.1 introduced, so on 1.2 the full remedy is a newer release or a patched build.

What to do on each line

  • 4.x. Move to 4.2.1. Until then, set metastore.try.direct.sql to false where the metastore is reachable by anything other than HiveServer2, avoid native SAML mode on HiveServer2, and block outbound requests from Hive hosts to cloud metadata endpoints.
  • 3.1 and 2.3. Plan the Hive 4 upgrade, including the JDK 21 requirement, or take patched builds from a supplier that backports fixes. Until then, audit Avro tables for unexpected avro.schema.url values, restrict CREATE TABLE and CREATE FUNCTION to trusted roles, and use Ranger or SQL standard authorization rather than none.
  • 1.2. Treat it as two upgrades in one: Hive itself and the JDBC drivers every client uses. Until then, apply the same steps and keep HiveServer2 and the metastore off untrusted networks.

Hive shares its cluster with HDFS, YARN and often HBase, so check the Hadoop line too; see Apache Hadoop vulnerabilities by version.

Where OSSeva fits

OSSeva ships patched, signed builds of Apache Hive 1.2, 2.3 and 3.1 with the metastore schema unchanged, the bundled ZooKeeper and Curator patched in the same build, and transitive dependency patching for Jetty, Jackson, Netty and log4j, delivered as Maven artifacts, tarballs and RPMs with the JDBC driver included and VEX statements for scanner findings. OSSeva backports fixes of this class to the end-of-life release lines it patches. They are available now on the Patch, Assure and Operate tiers. Assure adds a HiveServer2 discovery, HA and lock manager review, an authentication, authorisation and UDF exposure audit, and an upgrade plan to Hive 4.2 including the metastore schema, and Operate adds 24/7 HiveServer2 and metastore monitoring with a 15-minute P1 response, a named senior Hive engineer and execution of the Hive 4 upgrade. See Apache Hive support and Hive extended support.

Tags

Apache HiveCVEHive 3Hive 4End of Life

Ready to get your open source under control?

Talk to an OSSeva engineer about CVE coverage, compliance, and migration support for your stack.