Apache
Apache Gravitino: vulnerabilities and CVEs
Apache Gravitino has 4 published vulnerabilities, 4 of them in the last 12 months. 2 are rated critical and 0 are listed by CISA as actively exploited.
CVEs4
Last 12 months4
Critical2
Actively exploited0
All vulnerabilities in the catalogue →⭐ Follow this technology
Latest vulnerabilities
| CVE | Severity | EPSS | Active exploitation | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-49876 | Medium (6.5) | 0.49% | — | Jul 13, 2026 | Authenticated SSRF in Gravitino JobManager allows server-side HTTP requests to internal network and cloud metadata endpoints via unvalidated job template URIs. A vulnerability in Apache Gravitino. This issue affects… |
| CVE-2026-41041 | Critical (9.1) | 0.60% | — | Jul 13, 2026 | URL path injection via unencoded user-supplied identifiers vulnerability in Apache Gravitino. This issue affects Apache Gravitino: from 1.0.0 before 1.2.1. Users are recommended to upgrade to version 1.2.1, which fixes… |
| CVE-2026-41042 | Critical (9.1) | 1.5% | — | Jul 8, 2026 | Unauthenticated callers can supply a malicious H2 JDBC URL through the testConnection API, which executes arbitrary Java code on the server via H2's INIT parameter. Vulnerability in Apache Gravitino. This issue affects… |
| CVE-2025-53648 | Medium (5.4) | 0.56% | — | Jun 30, 2026 | SQL misconfiguration in the Gravitino UI, in versions 1.0.0 and below, can allow a malicious user to read or truncate files. Users are recommended to upgrade to version 1.0.0, which fixes this issue. |
🎯 How it gets exploited (ATT&CK techniques)
Number of CVEs of this technology mapped to each exploitation or primary-impact technique.