THREATOPS
THREAT OPSThreat News › CVE-2026-73334: Apache Parquet Hadoop: File-controlled KMS URL is forwarded to pluggable KmsClient that skips host validation

CVE-2026-73334: Apache Parquet Hadoop: File-controlled KMS URL is forwarded to pluggable KmsClient that skips host validation

medoss_secPublished 2026-09-08

<p>Posted by Gidon Gershinsky on Sep 08</p>Severity: moderate<br /> <br /> Affected versions:<br /> <br /> - Apache Parquet Hadoop (org.apache.parquet.crypto.keytools:parquet-hadoop)<br /> 1.12 through 1.18.0<br /> <br /> Description:<br /> <br /> Potential vulnerability in the org.apache.parquet.crypto.keytools package<br /> in Apache parquet-java, versions 1.12 to 1.18.0<br /> This package helps

Indicators of compromise

Original source: https://seclists.org/oss-sec/2026/q3/675