VYPR

Avro SerDe

by Apache

CVEs (1)

  • CVE-2026-55976Aug 25, 2026
    risk 0.00cvss epss

    Server-Side Request Forgery (SSRF) in Avro SerDe schema resolution in Apache Hive before 4.2.1 allows an authenticated remote attacker with CREATE TABLE privilege to cause the Hive server to fetch an attacker-controlled URL when resolving the avro.schema.url table property on…