Threat Intelligence Database
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threat Intelligence
Click on any threat for detailed analysis and mitigation recommendations
Server side request forgery in Apache Impala versions 4.4.x and 4.5.x. (CVE-2026-57866)CVE-2026-57866 0 Apache Impala versions 4.4.x and 4.5.x contain a server-side request forgery (SSRF) vulnerability. Authenticated users with permission to execute the ai_generate_text() function can exploit this flaw to exfiltrate secrets from credential providers configured via the hadoop.security.credential.provider.path property in core-site.xml. The attacker must know the secret's key to retrieve the secret. No patch information is currently available. Join the discussion | GCVE Database | 09/09/2026, 12:32:13 UTC Added: 09/09/2026, 13:28:53 UTC |
CVE-2026-65181: CWE-913 Improper Control of Dynamically-Managed Code Resources in Apache Software Foundation Apache ImpalaCVE-2026-65181 0 Insufficient authorization of Data Source tables in Impala 2.7-4.5 allows a client with privileges to upload a file to remote storage and create a table to execute arbitrary Java code. Users are recommended to upgrade to version 4.5.2, which fixes this issue. Join the discussion | CVE Database V5 | 09/09/2026, 10:40:51 UTC Added: 09/09/2026, 10:53:06 UTC |
CVE-2026-57866: CWE-918 Server-Side Request Forgery (SSRF) in Apache Software Foundation Apache ImpalaCVE-2026-57866 0 Server side request forgery in Apache Impala versions 4.4.x and 4.5.x. Authenticated Impala users with permissions to execute the ai_generate_text() function can exfiltrate secrets provided by the credential providers configured in the `hadoop.security.credential.provider.path` property of `core-site.xml`. The secret's key must be known to the user. Join the discussion | CVE Database V5 | 09/09/2026, 10:39:47 UTC Added: 09/09/2026, 10:53:06 UTC |
CVE-2026-56207: CWE-347 Improper Verification of Cryptographic Signature in Apache Software Foundation Apache ImpalaCVE-2026-56207 0 Signature of Bearer token is not verified in last step of SAML2 authentication for Impala's hs2-http interface, allowing altering user name and acting as another user. This issue affects Apache Impala: >=4.0.0. Users are recommended to upgrade to version 4.5.2, which fixes this issue. Join the discussion | CVE Database V5 | 09/09/2026, 12:32:13 UTC Added: 09/09/2026, 10:53:06 UTC |
CVE-2026-54048: CWE-918 Server-Side Request Forgery (SSRF) in Apache Software Foundation Apache ImpalaCVE-2026-54048 0 Specifying tblproperties('avro.schema.url'=' http://...' ) or with a 'file:///' URI on a table in Impala 2.0.0 to 4.5.1 on all platforms allows an attacker to trigger a GET request to internal endpoints they may not have access to but that Impala does and the response my be exposed via parsing error messages. Users are recommended to upgrade to version 4.5.2, which fixes this issue. Join the discussion | CVE Database V5 | 09/09/2026, 12:32:13 UTC Added: 09/09/2026, 10:53:06 UTC |
Showing 1 to 5 of 5 results