THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-65321 (CRITICAL 9.8) — PyAthena prior to 3.35.4 contains a sql injection vulnerability that allows unauthenticated attackers to inject arbitrary SQL by exploiting improper quote-escaping in DefaultParameterFormatter.format(), which routes DELETE and CTAS statements to the _escape_hive function that bac

[NVD] CVE-2026-65321 (CRITICAL 9.8) — PyAthena prior to 3.35.4 contains a sql injection vulnerability that allows unauthenticated attackers to inject arbitrary SQL by exploiting improper quote-escaping in DefaultParameterFormatter.format(), which routes DELETE and CTAS statements to the _escape_hive function that bac

mednvdPublished 2026-08-02

CVE-2026-65321 CVSS: 9.8 CRITICAL Published: 2026-08-02T15:16:33.957

PyAthena prior to 3.35.4 contains a sql injection vulnerability that allows unauthenticated attackers to inject arbitrary SQL by exploiting improper quote-escaping in DefaultParameterFormatter.format(), which routes DELETE and CTAS statements to the _escape_hive function that backslash-escapes single quotes rather than doubling

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-65321