CVE-2026-65321: CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in laughingman7743 PyAthena
PyAthena prior to 3.35.4 contains a sql injection vulnerability that allows unauthenticated attackers to inject arbitrary SQL by exploiting improper quote-escaping in DefaultParameterFormatter.format(), which routes DELETE and CTAS statements to the _escape_hive function that backslash-escapes single quotes rather than doubling them. Because Athena and Trino do not treat backslashes as escape characters inside string literals, attacker-supplied input such as a single quote followed by SQL syntax causes the parser to terminate the string literal prematurely, enabling data exfiltration via UNION SELECT, execution of destructive statements, and attacker-controlled CTAS destination and content.
AI Analysis
Technical Summary
CVE-2026-65321 is a critical SQL injection vulnerability in PyAthena before version 3.35.4. The vulnerability arises from improper neutralization of special elements in SQL commands, specifically in the DefaultParameterFormatter.format() method. This method routes DELETE and CTAS statements to the _escape_hive function, which incorrectly escapes single quotes by prefixing them with backslashes rather than doubling them. Because Athena and Trino SQL engines do not treat backslashes as escape characters within string literals, attacker-supplied input containing a single quote followed by SQL syntax can break out of the intended string context. This allows attackers to execute arbitrary SQL commands, including UNION SELECT for data exfiltration, destructive statements, and attacker-controlled CTAS operations.
Potential Impact
The vulnerability allows unauthenticated attackers to perform SQL injection attacks against PyAthena, potentially leading to unauthorized data access, data exfiltration, execution of destructive SQL commands, and manipulation of CTAS (CREATE TABLE AS SELECT) operations. This can compromise the confidentiality, integrity, and availability of the affected system's data.
Mitigation Recommendations
A fix is available in PyAthena version 3.35.4. Users should upgrade to version 3.35.4 or later to remediate this SQL injection vulnerability. Patch status is not explicitly stated beyond the version indication, so users should verify the vendor advisory for the latest remediation guidance.
CVE-2026-65321: CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in laughingman7743 PyAthena
Description
PyAthena prior to 3.35.4 contains a sql injection vulnerability that allows unauthenticated attackers to inject arbitrary SQL by exploiting improper quote-escaping in DefaultParameterFormatter.format(), which routes DELETE and CTAS statements to the _escape_hive function that backslash-escapes single quotes rather than doubling them. Because Athena and Trino do not treat backslashes as escape characters inside string literals, attacker-supplied input such as a single quote followed by SQL syntax causes the parser to terminate the string literal prematurely, enabling data exfiltration via UNION SELECT, execution of destructive statements, and attacker-controlled CTAS destination and content.
CVSS v4.0
Score 9.3critical
Affected software
laughingman7743
PyAthena
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-65321 is a critical SQL injection vulnerability in PyAthena before version 3.35.4. The vulnerability arises from improper neutralization of special elements in SQL commands, specifically in the DefaultParameterFormatter.format() method. This method routes DELETE and CTAS statements to the _escape_hive function, which incorrectly escapes single quotes by prefixing them with backslashes rather than doubling them. Because Athena and Trino SQL engines do not treat backslashes as escape characters within string literals, attacker-supplied input containing a single quote followed by SQL syntax can break out of the intended string context. This allows attackers to execute arbitrary SQL commands, including UNION SELECT for data exfiltration, destructive statements, and attacker-controlled CTAS operations.
Potential Impact
The vulnerability allows unauthenticated attackers to perform SQL injection attacks against PyAthena, potentially leading to unauthorized data access, data exfiltration, execution of destructive SQL commands, and manipulation of CTAS (CREATE TABLE AS SELECT) operations. This can compromise the confidentiality, integrity, and availability of the affected system's data.
Mitigation Recommendations
A fix is available in PyAthena version 3.35.4. Users should upgrade to version 3.35.4 or later to remediate this SQL injection vulnerability. Patch status is not explicitly stated beyond the version indication, so users should verify the vendor advisory for the latest remediation guidance.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- VulnCheck
- Date Reserved
- 2026-07-21T20:57:44.880Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 6a6f5fd5bf32cb7a34b6ff3a
Added to database: 08/02/2026, 15:18:45 UTC
Last enriched: 08/10/2026, 13:58:57 UTC
Last updated: 09/16/2026, 10:01:33 UTC
Views: 77
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.