Apache
Apache Polaris: vulnerabilidades y CVE
Apache Polaris tiene 6 vulnerabilidades publicadas, 6 de ellas en los últimos 12 meses. 4 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE6
Últimos 12 meses6
Críticas4
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-97395 | Alta (8.1) | 0.28% | — | 29 sept 2026 | Apache Polaris allows an authenticated principal with permission to create or update Iceberg table properties to set FileIO client settings such as s3.endpoint in table metadata. In versions < 1.8.0, when Polaris… |
| CVE-2026-64640 | Media (5.3) | 0.49% | — | 6 ago 2026 | Apache Polaris did not consistently validate storage locations supplied during table and view registration. An authenticated principal with permission to register a table or view could, depending on the affected release… |
| CVE-2026-42812 | Crítica (9.4) | 0.59% | — | 4 may 2026 | In Apache Iceberg, the table's metadata files are control files: they tell readers which data files belong to the table and which table version to read. `write.metadata.path` is an optional table property that tells… |
| CVE-2026-42811 | Crítica (9.4) | 0.72% | — | 4 may 2026 | In plain terms, Apache Polaris is supposed to issue short-lived GCS credentials that only work for one table's files, but a crafted namespace or table name can cause those credentials to work across the configured… |
| CVE-2026-42810 | Crítica (9.4) | 0.69% | — | 4 may 2026 | Apache Polaris accepts literal `*` characters in namespace and table names. When it later builds temporary S3 access policies for delegated table access, those same characters appear to be reused unescaped in S3 IAM… |
| CVE-2026-42809 | Crítica (9.4) | 0.58% | — | 4 may 2026 | Apache Polaris can issue broad temporary ("vended") storage credentials during staged table creation before the effective table location has been validated or durably reserved. Those temporary credentials are meant to… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.