CVE-2026-35194
Apache Flink: code injection in SQL code generation runs code on TaskManagers
Technology
Apache Flink
CVSS Score
8.1 / 10.0
Affected Versions
Apache Flink 1.15.0 to 1.20.3, 2.0.0 to 2.0.1, 2.1.0 to 2.1.1, 2.2.0
Upstream Fix
1.20.4, 2.0.2, 2.1.2, 2.2.1; no fix for 1.19 or older
Published
May 15, 2026
OSSeva Coverage
Fixed upstream
Description
Flink SQL code generation interpolates user-controlled strings into generated Java code without proper escaping, so an authenticated user who can submit queries can break out of a string literal and run arbitrary code on TaskManagers. JSON functions are affected from 1.15.0 and LIKE expressions with an ESCAPE clause from 1.17.0.
Is your Apache Flink deployment affected?
If you're running Apache Flink 1.15.0 to 1.20.3, 2.0.0 to 2.0.1, 2.1.0 to 2.1.1, 2.2.0, you need this patch. Book a discovery call to get covered.