Skip to main content

Vendor/product archive

apache / polaris CVEs

Beta · best-effort

4 CVEs tagged to apache / polaris4 Critical, 0 High, 0 Medium, 0 Low, 0 Unrated.

CVE-2026-42812

Published May 4, 2026

In Apache Iceberg, the table's metadata files are control files: they tell readers which data files belong to the table and which table version to read. `write.metadata.path` i…

CVSS 9.4 · Critical
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2026-42811

Published May 4, 2026

In plain terms, Apache Polaris is supposed to issue short-lived GCS credentials that only work for one table's files, but a crafted namespace or table name can cause those credent…

CVSS 9.4 · Critical
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2026-42810

Published May 4, 2026

Apache Polaris accepts literal `*` characters in namespace and table names. When it later builds temporary S3 access policies for delegated table access, those same characters app…

CVSS 9.4 · Critical
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2026-42809

Published May 4, 2026

Apache Polaris can issue broad temporary ("vended") storage credentials during staged table creation before the effective table location has been validated or durably reserved. T…

CVSS 9.4 · Critical
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort
Showing 1-4 of 4 CVEsPage 1 of 1