Amazon
Amazon Athena Odbc: vulnerabilities and CVEs
Amazon Athena Odbc has 6 published vulnerabilities, 6 of them in the last 12 months. 2 are rated critical and 0 are listed by CISA as actively exploited.
CVEs6
Last 12 months6
Critical2
Actively exploited0
All vulnerabilities in the catalogue →⭐ Follow this technology
Latest vulnerabilities
| CVE | Severity | EPSS | Active exploitation | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-5485 | High (7.3) | 1.1% | — | Apr 3, 2026 | OS command injection in the browser-based authentication component in Amazon Athena ODBC driver before 2.0.5.1 on Linux might allow a threat actor to execute arbitrary code by using specially crafted connection… |
| CVE-2026-35562 | High (8.7) | 0.68% | — | Apr 3, 2026 | Allocation of resources without limits in the parsing components in Amazon Athena ODBC driver before 2.1.0.0 might allow a threat actor to cause a denial of service by delivering crafted input that triggers excessive… |
| CVE-2026-35561 | Critical (9.1) | 0.74% | — | Apr 3, 2026 | Insufficient authentication security controls in the browser-based authentication components in Amazon Athena ODBC driver before 2.1.0.0 might allow a threat actor to intercept or hijack authentication sessions due to… |
| CVE-2026-35560 | Critical (9.1) | 0.36% | — | Apr 3, 2026 | Improper certificate validation in the identity provider connection components in Amazon Athena ODBC driver before 2.1.0.0 might allow a man-in-the-middle threat actor to intercept authentication credentials due to… |
| CVE-2026-35559 | High (7.1) | 0.51% | — | Apr 3, 2026 | Out-of-bounds write in the query processing components in Amazon Athena ODBC driver before 2.1.0.0 might allow a threat actor to crash the driver by using specially crafted data that is processed by the driver during… |
| CVE-2026-35558 | High (7.3) | 0.33% | — | Apr 3, 2026 | Improper neutralization of special elements in the authentication components in Amazon Athena ODBC driver before 2.1.0.0 might allow a threat actor to execute arbitrary code or redirect authentication flows by using… |