Apache Polaris vulnerabilities
4 known vulnerabilities affecting apache/polaris.
Total CVEs
4
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL4
Vulnerabilities
Page 1 of 1
CVE-2026-42810P2CRITICALCVSS 9.9fixed in 1.4.12026-05-04
CVE-2026-42810 [CRITICAL] CWE-20 CVE-2026-42810: Apache Polaris accepts literal `*` characters in namespace and table names. When it later builds tem
Apache Polaris accepts literal `*` characters in namespace and table names. When it
later builds temporary S3 access policies for delegated table access, those
same characters appear to be reused unescaped in S3 IAM resource patterns
and
`s3:prefix` conditions.
In S3 IAM policy matching, `*` is treated as a wildcard rather than as
ordinary text.
nvd
CVE-2026-42811P2CRITICALCVSS 9.9fixed in 1.4.12026-05-04
CVE-2026-42811 [CRITICAL] CWE-20 CVE-2026-42811: In plain terms, Apache Polaris is supposed to issue short-lived GCS credentials that only work for o
In plain terms, Apache Polaris is supposed to issue short-lived GCS credentials
that
only work for one table's files, but a crafted namespace or table name can
cause those credentials to work across the configured bucket instead.
Apache Polaris builds Google Cloud Storage downscoped credentials by creating a
Credential Access Boundary (CAB) with
nvd
CVE-2026-42812P2CRITICALCVSS 9.9fixed in 1.4.12026-05-04
CVE-2026-42812 [CRITICAL] CWE-20 CVE-2026-42812: In Apache Iceberg, the table's metadata files are control files: they tell readers which data files
In Apache Iceberg, the table's metadata files are control files: they tell readers
which data files belong to the table and which table version to read.
`write.metadata.path` is an optional table property that tells Polaris
where to
write those metadata files.
For a table already registered in a
Polaris-managed
catalog, changing only that property
nvd
CVE-2026-42809P2CRITICALCVSS 9.9fixed in 1.4.12026-05-04
CVE-2026-42809 [CRITICAL] CWE-20 CVE-2026-42809: Apache Polaris can issue broad temporary ("vended") storage credentials during staged table creation
Apache Polaris can issue broad temporary ("vended") storage credentials during
staged
table creation before the effective table location has been validated or
durably reserved.
Those temporary credentials are meant to limit the scope
of
accessible table data and metadata, but this scope limitation becomes
attacker-
directed because the attacker can
nvd