THREATOPS
THREAT OPSThreat News › CVE-2026-54048: Apache Impala: Avro Schema URL Server-Side Request Forgery

CVE-2026-54048: Apache Impala: Avro Schema URL Server-Side Request Forgery

medoss_secPublished 2026-09-08

<p>Posted by Michael Smith on Sep 08</p>Severity: important <br /> <br /> Affected versions:<br /> <br /> - Apache Impala 2.0.0 through 4.5.1<br /> <br /> Description:<br /> <br /> Specifying tblproperties(&apos;avro.schema.url&apos;=&apos; <a href="http://...&amp;apos" rel="nofollow">http://...&apos;</a>; ) or with a &apos;file:///&apos; URI on a table in Impala 2.0.0 to 4.5.1 <br /> on all platf

Indicators of compromise

Original source: https://seclists.org/oss-sec/2026/q3/685