Skip to main content
EPSS 1.0%top 40%

CVE-2026-65321: CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in laughingman7743 PyAthena

0
Critical
VulnerabilityCVE-2026-65321cvecve-2026-65321cwe-89
Published: 08/02/2026 (08/02/2026, 14:56:28 UTC)
Source: CVE Database V5
Vendor/Project: laughingman7743
Product: PyAthena

Description

PyAthena prior to 3.35.4 contains a sql injection vulnerability that allows unauthenticated attackers to inject arbitrary SQL by exploiting improper quote-escaping in DefaultParameterFormatter.format(), which routes DELETE and CTAS statements to the _escape_hive function that backslash-escapes single quotes rather than doubling them. Because Athena and Trino do not treat backslashes as escape characters inside string literals, attacker-supplied input such as a single quote followed by SQL syntax causes the parser to terminate the string literal prematurely, enabling data exfiltration via UNION SELECT, execution of destructive statements, and attacker-controlled CTAS destination and content.

CVSS v4.0

Score 9.3critical

Attack Vector
Network
Attack Complexity
Low
Attack Requirements
None
Privileges Required
None
User Interaction
None
Vuln. Confidentiality
High
Vuln. Integrity
High
Vuln. Availability
High
Subsq. Confidentiality
None
Subsq. Integrity
None
Subsq. Availability
None
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

Affected software

laughingman7743

PyAthena

Affected versions
>=0 <=3.35.3
pyathena
pkg:pypi/pyathena
Affected versions
<3.35.4

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/10/2026, 13:58:57 UTC

Technical Analysis

CVE-2026-65321 is a critical SQL injection vulnerability in PyAthena before version 3.35.4. The vulnerability arises from improper neutralization of special elements in SQL commands, specifically in the DefaultParameterFormatter.format() method. This method routes DELETE and CTAS statements to the _escape_hive function, which incorrectly escapes single quotes by prefixing them with backslashes rather than doubling them. Because Athena and Trino SQL engines do not treat backslashes as escape characters within string literals, attacker-supplied input containing a single quote followed by SQL syntax can break out of the intended string context. This allows attackers to execute arbitrary SQL commands, including UNION SELECT for data exfiltration, destructive statements, and attacker-controlled CTAS operations.

Potential Impact

The vulnerability allows unauthenticated attackers to perform SQL injection attacks against PyAthena, potentially leading to unauthorized data access, data exfiltration, execution of destructive SQL commands, and manipulation of CTAS (CREATE TABLE AS SELECT) operations. This can compromise the confidentiality, integrity, and availability of the affected system's data.

Mitigation Recommendations

A fix is available in PyAthena version 3.35.4. Users should upgrade to version 3.35.4 or later to remediate this SQL injection vulnerability. Patch status is not explicitly stated beyond the version indication, so users should verify the vendor advisory for the latest remediation guidance.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Data Version
5.2
Assigner Short Name
VulnCheck
Date Reserved
2026-07-21T20:57:44.880Z
Cvss Version
4.0
State
PUBLISHED

Threat ID: 6a6f5fd5bf32cb7a34b6ff3a

Added to database: 08/02/2026, 15:18:45 UTC

Last enriched: 08/10/2026, 13:58:57 UTC

Last updated: 09/16/2026, 10:01:33 UTC

Views: 77

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses