Back to Vulnerability Directory
CRITICALFixed upstream
CVE-2026-55976
Apache Hive: SSRF through avro.schema.url in the Avro SerDe
Technology
Apache Hive
CVSS Score
9.1 / 10.0
Affected Versions
Apache Hive 2.1.0 to 4.2.0
Upstream Fix
4.2.1; no fix for 2.x, 3.x, 4.0 or 4.1
Published
August 25, 2026
OSSeva Coverage
Fixed upstream
Description
An authenticated user with CREATE TABLE privilege can set the avro.schema.url table property on an Avro table, and the Hive server fetches that URL when the table is queried. This can expose cloud instance metadata, internal network services or local files to the Hive process identity. No admin rights are needed.
Is your Apache Hive deployment affected?
If you're running Apache Hive 2.1.0 to 4.2.0, you need this patch. Book a discovery call to get covered.