Specifying tblproperties('avro.schema.url'=' http://...' ) or with a 'file:///' URI on a table in Impala 2.0.0 to 4.5.1 on all platforms all…

cve CVE-2026-54048 1 source, 1 claim · Watch

NVD writes:
Specifying tblproperties('avro.schema.url'=' http://...' ) or with a 'file:///' URI on a table in Impala 2.0.0 to 4.5.1 on all platforms allows an attacker to trigger a GET request to internal endpoints they may not have access to but that Impala does and the response my be exposed via parsing error messages. Users are recommended to upgrade to version 4.5.2, which fixes this issue. the claim
Severity
MEDIUM NVD
CVSS
5.3 NVD
Vendor
Apache Software Foundation NVD
Product
Apache Impala NVD
CWE
CWE-918 NVD

How far exploitation has got

  1. No public code known
  2. Proof of concept
  3. Proof of concept, verified
  4. A Metasploit module
  5. Exploited in the wild
  6. Used in ransomware campaigns

Timeline

2026-09-09first spoke of it: Specifying tblproperties('avro.schema.url'=' http://...' ) or with a 'file:///' URI on a table in Impala 2.0.0 to 4.5.1 on all platforms allows an attacker to trigger a GET request to internal endpoints they may not have access to but that Impala does and the response my be exposed via parsing error messages. Users are recommended to upgrade to version 4.5.2, which fixes this issue.NVD

Specifying tblproperties('avro.schema.url'=' http://...' ) or with a 'file:///' URI on a table in Impala 2.0.0 to 4.5.1 on all platforms allows an attacker to trigger a GET request to internal endpoints they may not have access to but that Impala does and the response my be exposed via parsing error messages. Users are recommended to upgrade to version 4.5.2, which fixes this issue.

What it is to other things

affectsapache/impala
NVD
made_byapache
NVD

In words only, so not counted until a person confirms one:

made_byapache_software_foundation
NVD says “Apache Software Foundation”
affectsapache_software_foundation/apache_impala
NVD says “Apache Software Foundation · Apache Impala”
Every value, with what each source said and its receipt
PropertySourceSaidMeans here
Automatable
automatable
NVDyes
An attacker can reliably run all of the kill chain's first four steps without a person.
receipt
Source
NVD
Its words
yes
Read by
field:cve.metrics.ssvcV203[].ssvcData.options[].automatable
Said since
2026-10-06 12:31 UTC
Last answered
2026-10-06 12:41 UTC
Original
open at the source
2026-10-06 12:31 UTCyes
2026-09-29 09:45 UTC—
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "defaultStatus": "unaffected",
            "product": "Apache Impala",
            "vendor": "Apache Software Foundation",
            "versions": [
              {
                "lessThanOrEqual": "4.5.1",
                "status": "affected",
                "version": "2.0.0",
                "versionType": "semver"
              }
            ]
          }
        ],
        "source": "security@apache.org"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:apache:impala:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "C927FE5B-044E-4947-B505-0B76CBE31E9E",
                "versionEndExcluding": "4.5.2",
                "versionStartIncluding": "2.7.0",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "Specifying tblproperties('avro.schema.url'=' http://...' ) or with a 'file:///' URI on a table in Impala 2.0.0 to 4.5.1 on all platforms allows an attacker to trigger a GET request to internal endpoints they may not have access to but that Impala does and the response my be exposed via parsing error messages.\nUsers are recommended to upgrade to version 4.5.2, which fixes this issue."
      }
    ],
    "id": "CVE-2026-54048",
    "lastModified": "2026-09-10T20:38:42.430",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 5.3,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "LOW",
            "integrityImpact": "NONE",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
            "version": "3.1"
          },
          "exploitabilityScore": 3.9,
          "impactScore": 1.4,
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2026-54048",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "yes"
              },
              {
                "technicalImpact": "partial"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-09-10T17:58:58.345579Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2026-09-09T11:17:14.700",
    "references": [
      {
        "source": "security@apache.org",
        "tags": [
          "Mailing List",
          "Vendor Advisory"
        ],
        "url": "https://lists.apache.org/thread/cn3q4s8yx924ndlm3gt04o6g4rfm980c"
      },
      {
        "source": "af854a3a-2127-422b-91ae-364da2661108",
        "tags": [
          "Mailing List",
          "Third Party Advisory"
        ],
        "url": "http://www.openwall.com/lists/oss-security/2026/09/08/21"
      }
    ],
    "sourceIdentifier": "security@apache.org",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-918"
          }
        ],
        "source": "security@apache.org",
        "type": "Secondary"
      }
    ]
  }
}
—
CVSS
cvss
NVD5.3
receipt
Source
NVD
Its words
5.3
Read by
field:cve.metrics.cvssMetricV31[type=Primary].cvssData.baseScore || field:cve.metrics.cvssMetricV31[].cvssData.baseScore
Said since
2026-09-29 09:45 UTC
Last answered
2026-10-06 12:41 UTC
Original
open at the source
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "defaultStatus": "unaffected",
            "product": "Apache Impala",
            "vendor": "Apache Software Foundation",
            "versions": [
              {
                "lessThanOrEqual": "4.5.1",
                "status": "affected",
                "version": "2.0.0",
                "versionType": "semver"
              }
            ]
          }
        ],
        "source": "security@apache.org"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:apache:impala:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "C927FE5B-044E-4947-B505-0B76CBE31E9E",
                "versionEndExcluding": "4.5.2",
                "versionStartIncluding": "2.7.0",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "Specifying tblproperties('avro.schema.url'=' http://...' ) or with a 'file:///' URI on a table in Impala 2.0.0 to 4.5.1 on all platforms allows an attacker to trigger a GET request to internal endpoints they may not have access to but that Impala does and the response my be exposed via parsing error messages.\nUsers are recommended to upgrade to version 4.5.2, which fixes this issue."
      }
    ],
    "id": "CVE-2026-54048",
    "lastModified": "2026-09-10T20:38:42.430",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 5.3,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "LOW",
            "integrityImpact": "NONE",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
            "version": "3.1"
          },
          "exploitabilityScore": 3.9,
          "impactScore": 1.4,
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2026-54048",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "yes"
              },
              {
                "technicalImpact": "partial"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-09-10T17:58:58.345579Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2026-09-09T11:17:14.700",
    "references": [
      {
        "source": "security@apache.org",
        "tags": [
          "Mailing List",
          "Vendor Advisory"
        ],
        "url": "https://lists.apache.org/thread/cn3q4s8yx924ndlm3gt04o6g4rfm980c"
      },
      {
        "source": "af854a3a-2127-422b-91ae-364da2661108",
        "tags": [
          "Mailing List",
          "Third Party Advisory"
        ],
        "url": "http://www.openwall.com/lists/oss-security/2026/09/08/21"
      }
    ],
    "sourceIdentifier": "security@apache.org",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-918"
          }
        ],
        "source": "security@apache.org",
        "type": "Secondary"
      }
    ]
  }
}
—
CVSS vector
cvss_vector
NVDCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
receipt
Source
NVD
Its words
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Read by
field:cve.metrics.cvssMetricV31[type=Primary].cvssData.vectorString || field:cve.metrics.cvssMetricV31[].cvssData.vectorString
Said since
2026-10-06 12:31 UTC
Last answered
2026-10-06 12:41 UTC
Original
open at the source
2026-10-06 12:31 UTCCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
2026-09-29 09:45 UTC—
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "defaultStatus": "unaffected",
            "product": "Apache Impala",
            "vendor": "Apache Software Foundation",
            "versions": [
              {
                "lessThanOrEqual": "4.5.1",
                "status": "affected",
                "version": "2.0.0",
                "versionType": "semver"
              }
            ]
          }
        ],
        "source": "security@apache.org"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:apache:impala:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "C927FE5B-044E-4947-B505-0B76CBE31E9E",
                "versionEndExcluding": "4.5.2",
                "versionStartIncluding": "2.7.0",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "Specifying tblproperties('avro.schema.url'=' http://...' ) or with a 'file:///' URI on a table in Impala 2.0.0 to 4.5.1 on all platforms allows an attacker to trigger a GET request to internal endpoints they may not have access to but that Impala does and the response my be exposed via parsing error messages.\nUsers are recommended to upgrade to version 4.5.2, which fixes this issue."
      }
    ],
    "id": "CVE-2026-54048",
    "lastModified": "2026-09-10T20:38:42.430",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 5.3,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "LOW",
            "integrityImpact": "NONE",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
            "version": "3.1"
          },
          "exploitabilityScore": 3.9,
          "impactScore": 1.4,
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2026-54048",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "yes"
              },
              {
                "technicalImpact": "partial"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-09-10T17:58:58.345579Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2026-09-09T11:17:14.700",
    "references": [
      {
        "source": "security@apache.org",
        "tags": [
          "Mailing List",
          "Vendor Advisory"
        ],
        "url": "https://lists.apache.org/thread/cn3q4s8yx924ndlm3gt04o6g4rfm980c"
      },
      {
        "source": "af854a3a-2127-422b-91ae-364da2661108",
        "tags": [
          "Mailing List",
          "Third Party Advisory"
        ],
        "url": "http://www.openwall.com/lists/oss-security/2026/09/08/21"
      }
    ],
    "sourceIdentifier": "security@apache.org",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-918"
          }
        ],
        "source": "security@apache.org",
        "type": "Secondary"
      }
    ]
  }
}
—
CWE
cwe
NVDCWE-918
receipt
Source
NVD
Its words
CWE-918
Read by
field:cve.weaknesses[].description[].value
Said since
2026-10-06 12:31 UTC
Last answered
2026-10-06 12:41 UTC
Original
open at the source
2026-10-06 12:31 UTCCWE-918
2026-09-29 09:45 UTC—
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "defaultStatus": "unaffected",
            "product": "Apache Impala",
            "vendor": "Apache Software Foundation",
            "versions": [
              {
                "lessThanOrEqual": "4.5.1",
                "status": "affected",
                "version": "2.0.0",
                "versionType": "semver"
              }
            ]
          }
        ],
        "source": "security@apache.org"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:apache:impala:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "C927FE5B-044E-4947-B505-0B76CBE31E9E",
                "versionEndExcluding": "4.5.2",
                "versionStartIncluding": "2.7.0",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "Specifying tblproperties('avro.schema.url'=' http://...' ) or with a 'file:///' URI on a table in Impala 2.0.0 to 4.5.1 on all platforms allows an attacker to trigger a GET request to internal endpoints they may not have access to but that Impala does and the response my be exposed via parsing error messages.\nUsers are recommended to upgrade to version 4.5.2, which fixes this issue."
      }
    ],
    "id": "CVE-2026-54048",
    "lastModified": "2026-09-10T20:38:42.430",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 5.3,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "LOW",
            "integrityImpact": "NONE",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
            "version": "3.1"
          },
          "exploitabilityScore": 3.9,
          "impactScore": 1.4,
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2026-54048",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "yes"
              },
              {
                "technicalImpact": "partial"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-09-10T17:58:58.345579Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2026-09-09T11:17:14.700",
    "references": [
      {
        "source": "security@apache.org",
        "tags": [
          "Mailing List",
          "Vendor Advisory"
        ],
        "url": "https://lists.apache.org/thread/cn3q4s8yx924ndlm3gt04o6g4rfm980c"
      },
      {
        "source": "af854a3a-2127-422b-91ae-364da2661108",
        "tags": [
          "Mailing List",
          "Third Party Advisory"
        ],
        "url": "http://www.openwall.com/lists/oss-security/2026/09/08/21"
      }
    ],
    "sourceIdentifier": "security@apache.org",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-918"
          }
        ],
        "source": "security@apache.org",
        "type": "Secondary"
      }
    ]
  }
}
—
Exploitation
exploitation
NVDnone
No evidence of exploitation, and no public proof of concept.
receipt
Source
NVD
Its words
none
Read by
field:cve.metrics.ssvcV203[].ssvcData.options[].exploitation
Said since
2026-10-06 12:31 UTC
Last answered
2026-10-06 12:41 UTC
Original
open at the source
2026-10-06 12:31 UTCnone
2026-09-29 09:45 UTC—
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "defaultStatus": "unaffected",
            "product": "Apache Impala",
            "vendor": "Apache Software Foundation",
            "versions": [
              {
                "lessThanOrEqual": "4.5.1",
                "status": "affected",
                "version": "2.0.0",
                "versionType": "semver"
              }
            ]
          }
        ],
        "source": "security@apache.org"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:apache:impala:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "C927FE5B-044E-4947-B505-0B76CBE31E9E",
                "versionEndExcluding": "4.5.2",
                "versionStartIncluding": "2.7.0",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "Specifying tblproperties('avro.schema.url'=' http://...' ) or with a 'file:///' URI on a table in Impala 2.0.0 to 4.5.1 on all platforms allows an attacker to trigger a GET request to internal endpoints they may not have access to but that Impala does and the response my be exposed via parsing error messages.\nUsers are recommended to upgrade to version 4.5.2, which fixes this issue."
      }
    ],
    "id": "CVE-2026-54048",
    "lastModified": "2026-09-10T20:38:42.430",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 5.3,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "LOW",
            "integrityImpact": "NONE",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
            "version": "3.1"
          },
          "exploitabilityScore": 3.9,
          "impactScore": 1.4,
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2026-54048",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "yes"
              },
              {
                "technicalImpact": "partial"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-09-10T17:58:58.345579Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2026-09-09T11:17:14.700",
    "references": [
      {
        "source": "security@apache.org",
        "tags": [
          "Mailing List",
          "Vendor Advisory"
        ],
        "url": "https://lists.apache.org/thread/cn3q4s8yx924ndlm3gt04o6g4rfm980c"
      },
      {
        "source": "af854a3a-2127-422b-91ae-364da2661108",
        "tags": [
          "Mailing List",
          "Third Party Advisory"
        ],
        "url": "http://www.openwall.com/lists/oss-security/2026/09/08/21"
      }
    ],
    "sourceIdentifier": "security@apache.org",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-918"
          }
        ],
        "source": "security@apache.org",
        "type": "Secondary"
      }
    ]
  }
}
—
Product
product
NVDApache Impala
receipt
Source
NVD
Its words
Apache Impala
Read by
field:cve.affected[].affectedData[].product
Said since
2026-09-29 17:49 UTC
Last answered
2026-10-06 12:41 UTC
Original
open at the source
2026-09-29 17:49 UTCApache Impala
2026-09-29 09:45 UTC—
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "defaultStatus": "unaffected",
            "product": "Apache Impala",
            "vendor": "Apache Software Foundation",
            "versions": [
              {
                "lessThanOrEqual": "4.5.1",
                "status": "affected",
                "version": "2.0.0",
                "versionType": "semver"
              }
            ]
          }
        ],
        "source": "security@apache.org"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:apache:impala:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "C927FE5B-044E-4947-B505-0B76CBE31E9E",
                "versionEndExcluding": "4.5.2",
                "versionStartIncluding": "2.7.0",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "Specifying tblproperties('avro.schema.url'=' http://...' ) or with a 'file:///' URI on a table in Impala 2.0.0 to 4.5.1 on all platforms allows an attacker to trigger a GET request to internal endpoints they may not have access to but that Impala does and the response my be exposed via parsing error messages.\nUsers are recommended to upgrade to version 4.5.2, which fixes this issue."
      }
    ],
    "id": "CVE-2026-54048",
    "lastModified": "2026-09-10T20:38:42.430",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 5.3,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "LOW",
            "integrityImpact": "NONE",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
            "version": "3.1"
          },
          "exploitabilityScore": 3.9,
          "impactScore": 1.4,
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2026-54048",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "yes"
              },
              {
                "technicalImpact": "partial"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-09-10T17:58:58.345579Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2026-09-09T11:17:14.700",
    "references": [
      {
        "source": "security@apache.org",
        "tags": [
          "Mailing List",
          "Vendor Advisory"
        ],
        "url": "https://lists.apache.org/thread/cn3q4s8yx924ndlm3gt04o6g4rfm980c"
      },
      {
        "source": "af854a3a-2127-422b-91ae-364da2661108",
        "tags": [
          "Mailing List",
          "Third Party Advisory"
        ],
        "url": "http://www.openwall.com/lists/oss-security/2026/09/08/21"
      }
    ],
    "sourceIdentifier": "security@apache.org",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-918"
          }
        ],
        "source": "security@apache.org",
        "type": "Secondary"
      }
    ]
  }
}
—
Severity
severity
NVDMEDIUM
From 4.0 to 6.9.
receipt
Source
NVD
Its words
MEDIUM
Read by
field:cve.metrics.cvssMetricV31[type=Primary].cvssData.baseSeverity || field:cve.metrics.cvssMetricV31[].cvssData.baseSeverity
Said since
2026-10-06 12:31 UTC
Last answered
2026-10-06 12:41 UTC
Original
open at the source
2026-10-06 12:31 UTCMEDIUM
2026-09-29 09:45 UTC—
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "defaultStatus": "unaffected",
            "product": "Apache Impala",
            "vendor": "Apache Software Foundation",
            "versions": [
              {
                "lessThanOrEqual": "4.5.1",
                "status": "affected",
                "version": "2.0.0",
                "versionType": "semver"
              }
            ]
          }
        ],
        "source": "security@apache.org"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:apache:impala:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "C927FE5B-044E-4947-B505-0B76CBE31E9E",
                "versionEndExcluding": "4.5.2",
                "versionStartIncluding": "2.7.0",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "Specifying tblproperties('avro.schema.url'=' http://...' ) or with a 'file:///' URI on a table in Impala 2.0.0 to 4.5.1 on all platforms allows an attacker to trigger a GET request to internal endpoints they may not have access to but that Impala does and the response my be exposed via parsing error messages.\nUsers are recommended to upgrade to version 4.5.2, which fixes this issue."
      }
    ],
    "id": "CVE-2026-54048",
    "lastModified": "2026-09-10T20:38:42.430",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 5.3,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "LOW",
            "integrityImpact": "NONE",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
            "version": "3.1"
          },
          "exploitabilityScore": 3.9,
          "impactScore": 1.4,
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2026-54048",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "yes"
              },
              {
                "technicalImpact": "partial"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-09-10T17:58:58.345579Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2026-09-09T11:17:14.700",
    "references": [
      {
        "source": "security@apache.org",
        "tags": [
          "Mailing List",
          "Vendor Advisory"
        ],
        "url": "https://lists.apache.org/thread/cn3q4s8yx924ndlm3gt04o6g4rfm980c"
      },
      {
        "source": "af854a3a-2127-422b-91ae-364da2661108",
        "tags": [
          "Mailing List",
          "Third Party Advisory"
        ],
        "url": "http://www.openwall.com/lists/oss-security/2026/09/08/21"
      }
    ],
    "sourceIdentifier": "security@apache.org",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-918"
          }
        ],
        "source": "security@apache.org",
        "type": "Secondary"
      }
    ]
  }
}
medium
Status
status
NVDAnalyzed
receipt
Source
NVD
Its words
Analyzed
Read by
field:cve.vulnStatus
Said since
2026-09-29 09:45 UTC
Last answered
2026-10-06 12:41 UTC
Original
open at the source
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "defaultStatus": "unaffected",
            "product": "Apache Impala",
            "vendor": "Apache Software Foundation",
            "versions": [
              {
                "lessThanOrEqual": "4.5.1",
                "status": "affected",
                "version": "2.0.0",
                "versionType": "semver"
              }
            ]
          }
        ],
        "source": "security@apache.org"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:apache:impala:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "C927FE5B-044E-4947-B505-0B76CBE31E9E",
                "versionEndExcluding": "4.5.2",
                "versionStartIncluding": "2.7.0",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "Specifying tblproperties('avro.schema.url'=' http://...' ) or with a 'file:///' URI on a table in Impala 2.0.0 to 4.5.1 on all platforms allows an attacker to trigger a GET request to internal endpoints they may not have access to but that Impala does and the response my be exposed via parsing error messages.\nUsers are recommended to upgrade to version 4.5.2, which fixes this issue."
      }
    ],
    "id": "CVE-2026-54048",
    "lastModified": "2026-09-10T20:38:42.430",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 5.3,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "LOW",
            "integrityImpact": "NONE",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
            "version": "3.1"
          },
          "exploitabilityScore": 3.9,
          "impactScore": 1.4,
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2026-54048",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "yes"
              },
              {
                "technicalImpact": "partial"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-09-10T17:58:58.345579Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2026-09-09T11:17:14.700",
    "references": [
      {
        "source": "security@apache.org",
        "tags": [
          "Mailing List",
          "Vendor Advisory"
        ],
        "url": "https://lists.apache.org/thread/cn3q4s8yx924ndlm3gt04o6g4rfm980c"
      },
      {
        "source": "af854a3a-2127-422b-91ae-364da2661108",
        "tags": [
          "Mailing List",
          "Third Party Advisory"
        ],
        "url": "http://www.openwall.com/lists/oss-security/2026/09/08/21"
      }
    ],
    "sourceIdentifier": "security@apache.org",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-918"
          }
        ],
        "source": "security@apache.org",
        "type": "Secondary"
      }
    ]
  }
}
—
Technical impact
technical_impact
NVDpartial
The attacker gains limited control, or limited information.
receipt
Source
NVD
Its words
partial
Read by
field:cve.metrics.ssvcV203[].ssvcData.options[].technicalImpact
Said since
2026-10-06 12:31 UTC
Last answered
2026-10-06 12:41 UTC
Original
open at the source
2026-10-06 12:31 UTCpartial
2026-09-29 09:45 UTC—
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "defaultStatus": "unaffected",
            "product": "Apache Impala",
            "vendor": "Apache Software Foundation",
            "versions": [
              {
                "lessThanOrEqual": "4.5.1",
                "status": "affected",
                "version": "2.0.0",
                "versionType": "semver"
              }
            ]
          }
        ],
        "source": "security@apache.org"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:apache:impala:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "C927FE5B-044E-4947-B505-0B76CBE31E9E",
                "versionEndExcluding": "4.5.2",
                "versionStartIncluding": "2.7.0",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "Specifying tblproperties('avro.schema.url'=' http://...' ) or with a 'file:///' URI on a table in Impala 2.0.0 to 4.5.1 on all platforms allows an attacker to trigger a GET request to internal endpoints they may not have access to but that Impala does and the response my be exposed via parsing error messages.\nUsers are recommended to upgrade to version 4.5.2, which fixes this issue."
      }
    ],
    "id": "CVE-2026-54048",
    "lastModified": "2026-09-10T20:38:42.430",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 5.3,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "LOW",
            "integrityImpact": "NONE",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
            "version": "3.1"
          },
          "exploitabilityScore": 3.9,
          "impactScore": 1.4,
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2026-54048",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "yes"
              },
              {
                "technicalImpact": "partial"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-09-10T17:58:58.345579Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2026-09-09T11:17:14.700",
    "references": [
      {
        "source": "security@apache.org",
        "tags": [
          "Mailing List",
          "Vendor Advisory"
        ],
        "url": "https://lists.apache.org/thread/cn3q4s8yx924ndlm3gt04o6g4rfm980c"
      },
      {
        "source": "af854a3a-2127-422b-91ae-364da2661108",
        "tags": [
          "Mailing List",
          "Third Party Advisory"
        ],
        "url": "http://www.openwall.com/lists/oss-security/2026/09/08/21"
      }
    ],
    "sourceIdentifier": "security@apache.org",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-918"
          }
        ],
        "source": "security@apache.org",
        "type": "Secondary"
      }
    ]
  }
}
—
Vendor
vendor
NVDApache Software Foundation
receipt
Source
NVD
Its words
Apache Software Foundation
Read by
field:cve.affected[].affectedData[].vendor
Said since
2026-09-29 17:49 UTC
Last answered
2026-10-06 12:41 UTC
Original
open at the source
2026-09-29 17:49 UTCApache Software Foundation
2026-09-29 09:45 UTC—
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "defaultStatus": "unaffected",
            "product": "Apache Impala",
            "vendor": "Apache Software Foundation",
            "versions": [
              {
                "lessThanOrEqual": "4.5.1",
                "status": "affected",
                "version": "2.0.0",
                "versionType": "semver"
              }
            ]
          }
        ],
        "source": "security@apache.org"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:apache:impala:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "C927FE5B-044E-4947-B505-0B76CBE31E9E",
                "versionEndExcluding": "4.5.2",
                "versionStartIncluding": "2.7.0",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "Specifying tblproperties('avro.schema.url'=' http://...' ) or with a 'file:///' URI on a table in Impala 2.0.0 to 4.5.1 on all platforms allows an attacker to trigger a GET request to internal endpoints they may not have access to but that Impala does and the response my be exposed via parsing error messages.\nUsers are recommended to upgrade to version 4.5.2, which fixes this issue."
      }
    ],
    "id": "CVE-2026-54048",
    "lastModified": "2026-09-10T20:38:42.430",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 5.3,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "LOW",
            "integrityImpact": "NONE",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
            "version": "3.1"
          },
          "exploitabilityScore": 3.9,
          "impactScore": 1.4,
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2026-54048",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "yes"
              },
              {
                "technicalImpact": "partial"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-09-10T17:58:58.345579Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2026-09-09T11:17:14.700",
    "references": [
      {
        "source": "security@apache.org",
        "tags": [
          "Mailing List",
          "Vendor Advisory"
        ],
        "url": "https://lists.apache.org/thread/cn3q4s8yx924ndlm3gt04o6g4rfm980c"
      },
      {
        "source": "af854a3a-2127-422b-91ae-364da2661108",
        "tags": [
          "Mailing List",
          "Third Party Advisory"
        ],
        "url": "http://www.openwall.com/lists/oss-security/2026/09/08/21"
      }
    ],
    "sourceIdentifier": "security@apache.org",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-918"
          }
        ],
        "source": "security@apache.org",
        "type": "Secondary"
      }
    ]
  }
}
—
Every claim, by kind

vulnerability

Specifying tblproperties('avro.schema.url'=' http://...' ) or with a 'file:///' URI on a table in Impala 2.0.0 to 4.5.1 on all platforms allows an attacker to trigger a GET request to internal endpoints they may not have access to but that Impala does and the response my be exposed via parsing error messages. Users are recommended to upgrade to version 4.5.2, which fixes this issue.
zetlyn/cve-nvd · 2026-09-09
automatable yes cvss 5.3 cvss_vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N cwe CWE-918 exploitation none product Apache Impala severity MEDIUM status Analyzed technical_impact partial vendor Apache Software Foundation source