Back to Vulnerability Directory
CRITICALFixed upstream

CVE-2026-55976

Apache Hive: SSRF through avro.schema.url in the Avro SerDe

Technology

Apache Hive

CVSS Score

9.1 / 10.0

Affected Versions

Apache Hive 2.1.0 to 4.2.0

Upstream Fix

4.2.1; no fix for 2.x, 3.x, 4.0 or 4.1

Published

August 25, 2026

OSSeva Coverage

Fixed upstream

Description

An authenticated user with CREATE TABLE privilege can set the avro.schema.url table property on an Avro table, and the Hive server fetches that URL when the table is queried. This can expose cloud instance metadata, internal network services or local files to the Hive process identity. No admin rights are needed.

Upstream record: NVD · CVE.org

Is your Apache Hive deployment affected?

If you're running Apache Hive 2.1.0 to 4.2.0, you need this patch. Book a discovery call to get covered.