CVE-2026-55976
Received Received - Intake

SSRF in Apache Hive via Avro SerDe Schema Resolution

Vulnerability report for CVE-2026-55976, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-25

Last updated on: 2026-08-25

Assigner: Apache Software Foundation

Description

Server-Side Request Forgery (SSRF) in Avro SerDe schema resolution in Apache Hive before 4.2.1 allows an authenticated remote attacker with CREATE TABLE privilege to cause the Hive server to fetch an attacker-controlled URL when resolving the avro.schema.urlΒ table property on an Avro table that is subsequently queried. This can expose cloud instance metadata, internal network services, or local server files to the Hive process identity. Users are recommended to upgrade to version 4.2.1, which fixes this issue. Attacker access requirements: * Network access to HiveServer2 / Metastore: required (remote attacker model). * Valid Hive authentication: required. * CREATE TABLE (or equivalent) privilege: required, so the attacker can set avro.schema.urlΒ in table properties. * SELECT privilege on the malicious table: not required for the creator, who can typically query their own table; any other user granted SELECT can also trigger the fetch. * Write access to the table LOCATION: not required; the attack uses the schema URL, not the data path. * Admin / superuser privileges: not required; an ordinary authenticated user with DDL rights is sufficient. * External tables enabled: typically required in practice, and enabled by default in most deployments. Detection guidance: * Inspect metastore / Hive table metadata for Avro tables whose avro.schema.urlΒ uses unexpected schemes such as http, https, file, or ftp, or points at link-local / cloud metadata addresses (for example 169.254.169.254) or other internal hosts. * Review HiveServer2 and Metastore logs around CREATE/ALTER TABLE and queries against Avro tables for schema-resolution failures or outbound fetches of avro.schema.url. * Correlate CREATE TABLE / ALTER TABLE activity that sets avro.schema.urlΒ with subsequent SELECT activity on the same table, especially when the URL target is unusual for schema distribution. * On cloud deployments, check instance / VPC flow logs and metadata service access logs for unexpected requests from Hive host identities shortly after Avro DDL or query activity.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-25
Last Modified
2026-08-25
Generated
2026-08-25
AI Q&A
2026-08-25
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
apache hive 4.2.1

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-918 The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a Server-Side Request Forgery (SSRF) vulnerability in Apache Hive before version 4.2.1. It allows an authenticated remote attacker with CREATE TABLE privilege to manipulate the avro.schema.url table property to force the Hive server to fetch an attacker-controlled URL. This can expose cloud instance metadata, internal network services, or local server files to the Hive process identity.

Detection Guidance
  • Inspect Hive metastore and table metadata for Avro tables with avro.schema.url using unexpected schemes like http, https, file, or ftp, or pointing to internal/cloud metadata addresses (e.g., 169.254.169.254).
  • Review HiveServer2 and Metastore logs for schema-resolution failures or outbound fetches of avro.schema.url around CREATE/ALTER TABLE and SELECT queries.
  • Correlate CREATE TABLE/ALTER TABLE activity setting avro.schema.url with subsequent SELECT queries on the same table, especially for unusual URL targets.
  • On cloud deployments, check VPC flow logs and metadata service access logs for unexpected requests from Hive host identities after Avro DDL or query activity.
Impact Analysis

An attacker could exploit this to access sensitive internal resources or files accessible by the Hive server. This includes cloud metadata services, internal network services, or local files on the server running Hive. The impact depends on the permissions of the Hive process identity and the network configuration.

Compliance Impact

This vulnerability could lead to unauthorized data access, potentially violating compliance requirements such as GDPR (data protection) or HIPAA (health information privacy). Unauthorized exposure of sensitive data or internal resources may result in regulatory penalties or breaches of compliance standards.

Mitigation Strategies
  • Upgrade Apache Hive to version 4.2.1 or later to apply the security fix for SSRF in Avro SerDe schema resolution.
  • Restrict allowed URI schemes for avro.schema.url in Hive configuration to only trusted schemes like hdfs, s3, or gs, and disable HTTP/HTTPS by default.
  • Implement stricter authorization checks for schema URLs, validating against configured allowed schemes and hosts when remote access is enabled.
  • Review and revoke unnecessary CREATE TABLE privileges for users to reduce attack surface.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-55976. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart