Back to Vulnerability Directory
HIGHFixed upstream

CVE-2026-35194

Apache Flink: code injection in SQL code generation runs code on TaskManagers

Technology

Apache Flink

CVSS Score

8.1 / 10.0

Affected Versions

Apache Flink 1.15.0 to 1.20.3, 2.0.0 to 2.0.1, 2.1.0 to 2.1.1, 2.2.0

Upstream Fix

1.20.4, 2.0.2, 2.1.2, 2.2.1; no fix for 1.19 or older

Published

May 15, 2026

OSSeva Coverage

Fixed upstream

Description

Flink SQL code generation interpolates user-controlled strings into generated Java code without proper escaping, so an authenticated user who can submit queries can break out of a string literal and run arbitrary code on TaskManagers. JSON functions are affected from 1.15.0 and LIKE expressions with an ESCAPE clause from 1.17.0.

Upstream record: NVD · CVE.org

Is your Apache Flink deployment affected?

If you're running Apache Flink 1.15.0 to 1.20.3, 2.0.0 to 2.0.1, 2.1.0 to 2.1.1, 2.2.0, you need this patch. Book a discovery call to get covered.