Skip to main content

Vendor/product archive

apache / gravitino CVEs

Beta · best-effort

3 CVEs tagged to apache / gravitino1 Critical, 0 High, 2 Medium, 0 Low, 0 Unrated.

CVE-2026-49876

Published Jul 13, 2026

Authenticated SSRF in Gravitino JobManager allows server-side HTTP requests to internal network and cloud metadata endpoints via unvalidated job template URIs. A vulnerability in…

CVSS 6.5 · Medium
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2026-41041

Published Jul 13, 2026

URL path injection via unencoded user-supplied identifiers vulnerability in Apache Gravitino. This issue affects Apache Gravitino: from 1.0.0 before 1.2.1. Users are recommended…

CVSS 9.1 · Critical
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2025-53648

Published Jun 30, 2026

SQL misconfiguration in the Gravitino UI, in versions 1.0.0 and below, can allow a malicious user to read or truncate files. Users are recommended to upgrade to version 1.0.0, whi…

CVSS 5.4 · Medium
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort
Showing 1-3 of 3 CVEsPage 1 of 1