THREAT OPS › Threat News › CVE-2026-54048: Apache Impala: Avro Schema URL Server-Side Request Forgery
CVE-2026-54048: Apache Impala: Avro Schema URL Server-Side Request Forgery
<p>Posted by Michael Smith on Sep 08</p>Severity: important <br /> <br /> Affected versions:<br /> <br /> - Apache Impala 2.0.0 through 4.5.1<br /> <br /> Description:<br /> <br /> Specifying tblproperties('avro.schema.url'=' <a href="http://...&apos" rel="nofollow">http://...'</a>; ) or with a 'file:///' URI on a table in Impala 2.0.0 to 4.5.1 <br /> on all platf
Indicators of compromise
- CVE-2026-54048cve
- http://...&aposurl
- http://...&aposurl
Original source: https://seclists.org/oss-sec/2026/q3/685