CVE-2026-35194
published 2026-05-15CVE-2026-35194: Code injection in SQL code generation in Apache Flink 1.15.0 through 1.20.x and 2.0.0 through 2.x allows authenticated users with query submission privileges…
PriorityP356high8.1CVSS 3.1
AVNACLPRLUINSUCHIHAN
EPSS
0.38%
30.3th percentile
Code injection in SQL code generation in Apache Flink 1.15.0 through 1.20.x and 2.0.0 through 2.x allows authenticated users with query submission privileges to execute arbitrary code on TaskManagers via maliciously crafted SQL queries. The vulnerability affects JSON functions (1.15.0+) and LIKE expressions with ESCAPE clauses (1.17.0+). User-controlled strings are interpolated into generated Java code without proper escaping, allowing attackers to break out of string literals and inject arbitrary expressions.
Users are recommended to upgrade to either version 1.20.4, 2.0.2, 2.1.2 or 2.2.1, which fixes this issue.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | flink | — | — |
| apache | flink | >= 1.15.0 < 1.20.4 | 1.20.4 |
| apache | flink | >= 2.0.0 < 2.0.2 | 2.0.2 |
| apache | flink | >= 2.1.0 < 2.1.2 | 2.1.2 |
| apache_software_foundation | apache_flink | >= 1.15.0 < 1.20.4,2.0.2,2.1.2,2.2.1 | 1.20.4,2.0.2,2.1.2,2.2.1 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-2f54-v4hm-fx73: Code injection in SQL code generation in Apache Flink 1
ghsa_unreviewed·2026-05-15
CVE-2026-35194 [HIGH] CWE-94 GHSA-2f54-v4hm-fx73: Code injection in SQL code generation in Apache Flink 1
Code injection in SQL code generation in Apache Flink 1.15.0 through 1.20.x and 2.0.0 through 2.x allows authenticated users with query submission privileges to execute arbitrary code on TaskManagers via maliciously crafted SQL queries. The vulnerability affects JSON functions (1.15.0+) and LIKE expressions with ESCAPE clauses (1.17.0+). User-controlled strings are interpolated into generated Java code without proper escaping, allowing attackers to break out of string literals and inject arbitrary expressions.
Users are recommended to upgrade to either version 1.20.4, 2.0.2, 2.1.2 or 2.2.1, which fixes this issue.
GHSA
Apache Flink: Remote code execution via SQL injection in code generation
ghsa·2026-05-15
CVE-2026-35194 [HIGH] CWE-94 Apache Flink: Remote code execution via SQL injection in code generation
Apache Flink: Remote code execution via SQL injection in code generation
Code injection in SQL code generation in Apache Flink 1.15.0 through 1.20.x and 2.0.0 through 2.x allows authenticated users with query submission privileges to execute arbitrary code on TaskManagers via maliciously crafted SQL queries. The vulnerability affects JSON functions (1.15.0+) and LIKE expressions with ESCAPE clauses (1.17.0+). User-controlled strings are interpolated into generated Java code without proper escaping, allowing attackers to break out of string literals and inject arbitrary expressions.
Users are recommended to upgrade to either version 1.20.4, 2.0.2, 2.1.2 or 2.2.1, which fixes this issue.
VulDB
Apache Flink up to 1.20.3/2.0.1/2.1.1/2.2.0 TaskManagers code injection (EUVD-2026-30550)
vuldb·2026-05-15·CVSS 8.1
CVE-2026-35194 [HIGH] Apache Flink up to 1.20.3/2.0.1/2.1.1/2.2.0 TaskManagers code injection (EUVD-2026-30550)
A vulnerability was found in Apache Flink up to 1.20.3/2.0.1/2.1.1/2.2.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the component TaskManagers. The manipulation results in code injection.
This vulnerability was named CVE-2026-35194. The attack may be performed from remote. There is no available exploit.
It is recommended to upgrade the affected component.
No detection rules found.
No public exploits indexed.
2026-05-15
Published