Apache Software Foundation Apache Gravitino vulnerabilities
4 known vulnerabilities affecting apache_software_foundation/apache_gravitino.
Total CVEs
4
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL2MEDIUM2
Vulnerabilities
Page 1 of 1
CVE-2026-41042P2CRITICALCVSS 9.1fixed in 1.2.12026-07-08
CVE-2026-41042 [CRITICAL] CWE-20 CVE-2026-41042: Unauthenticated callers can supply a malicious H2 JDBC URL through the testConnection API, which exe
Unauthenticated callers can supply a malicious H2 JDBC URL through the testConnection API, which executes arbitrary Java code on the server via H2's INIT parameter. Vulnerability in Apache Gravitino.
This issue affects Apache Gravitino: before 1.2.1.
Users are recommended to upgrade to version 1.2.1, which fixes the issue.
This issue only happen
nvd
CVE-2026-41041P3CRITICALCVSS 9.1≥ 1.0.0, < 1.2.12026-07-13
CVE-2026-41041 [CRITICAL] CWE-177 CVE-2026-41041: URL path injection via unencoded user-supplied identifiers vulnerability in Apache Gravitino. This
URL path injection via unencoded user-supplied identifiers vulnerability in Apache Gravitino.
This issue affects Apache Gravitino: from 1.0.0 before 1.2.1.
Users are recommended to upgrade to version 1.2.1, which fixes the issue.
nvd
CVE-2026-49876P3MEDIUMCVSS 6.5≥ 1.0.0, ≤ 1.2.12026-07-13
CVE-2026-49876 [MEDIUM] CWE-918 CVE-2026-49876: Authenticated SSRF in Gravitino JobManager allows server-side HTTP requests to internal network and
Authenticated SSRF in Gravitino JobManager allows server-side HTTP requests to internal network and cloud metadata endpoints via unvalidated job template URIs. A vulnerability in Apache Gravitino.
This issue affects Apache Gravitino: from 1.0.0 through 1.2.1.
Users are recommended to upgrade to version 1.3.0, which fixes the issue.
nvd
CVE-2025-53648P4MEDIUMCVSS 5.4≥ 0.5.0, < 1.0.02026-06-30
CVE-2025-53648 [MEDIUM] CWE-89 CVE-2025-53648: SQL misconfiguration in the Gravitino UI, in versions 1.0.0 and below, can allow a malicious user to
SQL misconfiguration in the Gravitino UI, in versions 1.0.0 and below, can allow a malicious user to read or truncate files.
Users are recommended to upgrade to version 1.0.0, which fixes this issue.
nvd