THREAT OPS › Threat News › [NVD] CVE-2026-65321 (CRITICAL 9.8) — PyAthena prior to 3.35.4 contains a sql injection vulnerability that allows unauthenticated attackers to inject arbitrary SQL by exploiting improper quote-escaping in DefaultParameterFormatter.format(), which routes DELETE and CTAS statements to the _escape_hive function that bac
[NVD] CVE-2026-65321 (CRITICAL 9.8) — PyAthena prior to 3.35.4 contains a sql injection vulnerability that allows unauthenticated attackers to inject arbitrary SQL by exploiting improper quote-escaping in DefaultParameterFormatter.format(), which routes DELETE and CTAS statements to the _escape_hive function that bac
CVE-2026-65321 CVSS: 9.8 CRITICAL Published: 2026-08-02T15:16:33.957
PyAthena prior to 3.35.4 contains a sql injection vulnerability that allows unauthenticated attackers to inject arbitrary SQL by exploiting improper quote-escaping in DefaultParameterFormatter.format(), which routes DELETE and CTAS statements to the _escape_hive function that backslash-escapes single quotes rather than doubling
Indicators of compromise
- CVE-2026-65321cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-65321