CLEANSTART-2026-QP89146

See a problem?
Import Source
https://github.com/cleanstart-dev/cleanstart-security-advisories/blob/main/advisories/2026/CLEANSTART-2026-QP89146.json
JSON Data
https://api.test.osv.dev/v1/vulns/CLEANSTART-2026-QP89146
Upstream
  • CVE-2026-41720
  • CVE-2026-41848
  • CVE-2026-41850
  • CVE-2026-41851
  • CVE-2026-41852
  • CVE-2026-57914
  • ghsa-2r2c-cx56-8933
  • ghsa-47qp-hqvx-6r3f
  • ghsa-mhm7-754m-9p8w
  • ghsa-r7wm-3cxj-wff9
Published
2026-09-10T03:06:13Z
Modified
2026-09-10T03:15:05Z
Severity
  • 9.8 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
Improper Control of Generation of Code ('Code Injection') vulnerability in Apache Avro Java SDK when generating specific records from untrusted Avro schemas
Details

Multiple security vulnerabilities affect the apache-hive package. Improper Control of Generation of Code ('Code Injection') vulnerability in Apache Avro Java SDK when generating specific records from untrusted Avro schemas. See references for individual vulnerability details.

References

Affected packages

CleanStart / apache-hive

Package

Name
apache-hive

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
4.1.0-r7

Database specific

source
"https://github.com/cleanstart-dev/cleanstart-security-advisories/blob/main/advisories/2026/CLEANSTART-2026-QP89146.json"