Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-73334— Apache Parquet Hadoop: File-controlled KMS URL is forwarded to pluggable KmsClient that skips host validation

Quick assessment

Affected
Apache Software Foundation Apache Parquet Hadoop
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

以下是该漏洞描述的中文翻译: Apache Parquet 的 包(版本 1.12 至 1.18)中可能存在以下问题: 该包允许用户通过信封加密机制对 Parquet 文件进行加密,其中数据密钥通过密钥管理服务(KMS)进行包装(加密)。 在读取端,KMS URL 可以由应用程序控制,也可以由文件控制。如果用户未使用应用程序控制来指定该参数,则文件中的 KMS URL 会被传递给可插拔的 实现。如果该可插拔实现未执行主机验证,攻击者可以通过在文件中设置的恶意主机接收 KMS 令牌。 在问题修复之前,建议用户在读取端

Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-73334

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Apache Parquet Hadoop: File-controlled KMS URL is forwarded to pluggable KmsClient that skips host validation
Source: CVE Program / CVE List V5
Vulnerability Description
Potential problem for users of the org.apache.parquet.crypto.keytools package in Apache Parquet, versions 1.12 to 1.18. This package enables users to encrypt Parquet files via an envelope encryption mechanism that wraps (encrypts) data keys via a Key Management Service (KMS).  On the reader side, the KMS URL can be application-controlled or file-controlled. If the user does not leverage application control for this parameter, a file-controlled KMS URL is forwarded to a pluggable KmsClient implementation. If the pluggable implementation does not perform host validation, a KMS token can be sent to a malicious host set by an attacker in the file. Before the problem is fixed, users are recommended to leverage application control for KMS URL parameter in readers (versions 1.12-1.18). After the problem is fixed (presumably in version 1.19), the upgrade will disable file-controlled KMS URL by default. Users of the KMS URL parameter  will have two options then: leverage application control for KMS URL parameter in readers, or enable file-controlled KMS URL (via a new app parameter). The latter option will explicitly require (in the new parameter documentation) to validate the KMS URL and use authentication in the custom implementation of the KMS client plug in.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
输入验证不恰当
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Apache Software Foundation Apache Parquet Hadoop 1.12 ~ 1.18.0 -

II. Public POCs for CVE-2026-73334

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-73334

登录查看更多情报信息。

Other References for CVE-2026-73334 (1)

Same Patch Batch · Apache Software Foundation · 2026-09-09 · 9 CVEs total

CVE-2026-74761 Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ: Spoofing of RemoveSubscripti
CVE-2026-41871 Apache Nutch: Unauthenticated reflection-based job execution in Nutch Server (Nutch REST A
CVE-2026-41869 Apache Nutch: Unauthenticated forced shutdown and job interruption in Nutch Server (Nutch
CVE-2026-41870 Apache Nutch: Unauthenticated remote code execution (RCE) via JEXL injection in Nutch Serv
CVE-2026-65181 Apache Impala: RCE via External Data Source Class Loading
CVE-2026-57866 Apache Impala: Secrets Exfiltration via SSRF
CVE-2026-56207 Apache Impala: SAML authentication bypass via forged bearer token
CVE-2026-54048 Apache Impala: Avro Schema URL Server-Side Request Forgery

IV. Related Vulnerabilities

V. Comments for CVE-2026-73334

No comments yet


Leave a comment