CVE-2026-55976: CWE-918 Server-Side Request Forgery (SSRF) in Apache Software Foundation Apache Hive
Description
CVE-2026-55976 is a critical Server-Side Request Forgery (SSRF) vulnerability in Apache Hive's Avro SerDe schema resolution prior to version 4.2.1. An authenticated attacker with CREATE TABLE privileges can cause the Hive server to fetch attacker-controlled URLs when resolving the avro.schema.url table property. This can lead to exposure of cloud instance metadata, internal network services, or local server files accessible to the Hive process identity. The vulnerability requires network access to HiveServer2 or Metastore and valid Hive authentication but does not require admin privileges. Users should upgrade to Apache Hive 4.2.1 to remediate this issue.
CVSS v3.1
Score 9.1critical
Affected software
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability in Apache Hive before 4.2.1 involves SSRF in the Avro SerDe schema resolution process. An attacker with CREATE TABLE privileges can specify a malicious avro.schema.url property that causes the Hive server to fetch data from attacker-controlled or sensitive internal URLs during query execution. This can expose sensitive internal resources such as cloud metadata services or local files to the Hive process identity. The attack requires network access to HiveServer2 or Metastore and valid authentication but does not require elevated admin rights. The issue is fixed in Apache Hive version 4.2.1.
Potential Impact
An authenticated attacker with CREATE TABLE privileges can exploit this SSRF vulnerability to make the Hive server fetch arbitrary URLs, potentially exposing sensitive internal resources such as cloud instance metadata, internal network services, or local server files. This can lead to information disclosure impacting confidentiality and integrity, but does not affect availability. The vulnerability has a CVSS score of 9.1 (critical).
Mitigation Recommendations
A fix is available in Apache Hive version 4.2.1. Users are strongly recommended to upgrade to this version to remediate the vulnerability. Detection can be aided by inspecting metastore and Hive table metadata for suspicious avro.schema.url values, reviewing HiveServer2 and Metastore logs for schema-resolution failures or unexpected outbound fetches, and monitoring cloud instance or VPC flow logs for unusual metadata service access. No temporary or alternative mitigations are specified beyond upgrading.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-gp8m-92x3-q87g
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-55976"]
- State
- PUBLISHED
Threat ID: 6a8d9ac3acd9273b493e0faf
Added to database: 08/25/2026, 13:38:11 UTC
Last enriched: 09/29/2026, 05:21:09 UTC
Last updated: 10/09/2026, 18:48:21 UTC
Views: 55
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.