VYPR

Impala

by Impala

CVEs (1)

  • CVE-2026-90466Oct 7, 2026
    risk 0.00cvss —epss —

    Path traversal of 'trusted_jar_paths' in Impala 4.5.2 allows an attacker-controlled JAR to be loaded via a relative path where the prefix matches a path specified in 'trusted_jar_paths'. The startup flag 'trusted_jar_paths' references URIs for loading files from local or…