Server-Side Request Forgery (SSRF) in Avro SerDe schema resolution in Apache Hive before 4.2.1 allows an authenticated remote attacker with CREATE TABLE privilege to cause the Hive server to fetch an attacker-controlled URL when resolving the avro.schema.url table property on an Avro table that is subsequently queried. This can expose cloud instance metadata, internal network services, or local server files to the Hive process identity. Users are recommended to upgrade to version 4.2.1, which fixes this issue.
Attacker access requirements:
Detection guidance:
{
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/55xxx/CVE-2026-55976.json",
"cwe_ids": [
"CWE-918"
],
"cna_assigner": "apache"
}[
{
"id": "CVE-2026-55976-19d00793",
"target": {
"file": "common/src/java/org/apache/hadoop/hive/conf/HiveConf.java"
},
"deprecated": false,
"digest": {
"threshold": 0.9,
"line_hashes": [
"311784074827836658899111507564614183533",
"49658095528386682630457350520660918190",
"279844878746238084325754052254045140892",
"230841615808349844440467684349608150286"
]
},
"signature_version": "v1",
"source": "https://github.com/apache/hive/commit/45049202df35cea382616624de3fe8d252aa2d00",
"signature_type": "Line"
},
{
"id": "CVE-2026-55976-1a29ae28",
"target": {
"function": "doAuthorization",
"file": "ql/src/java/org/apache/hadoop/hive/ql/security/authorization/command/CommandAuthorizerV2.java"
},
"deprecated": false,
"digest": {
"function_hash": "188037324645067891577541378222240526534",
"length": 796.0
},
"signature_version": "v1",
"source": "https://github.com/apache/hive/commit/45049202df35cea382616624de3fe8d252aa2d00",
"signature_type": "Function"
},
{
"id": "CVE-2026-55976-222afda6",
"target": {
"file": "ql/src/java/org/apache/hadoop/hive/ql/security/authorization/AuthorizationUtils.java"
},
"deprecated": false,
"digest": {
"threshold": 0.9,
"line_hashes": [
"297258043004301889296681696598004118558",
"265588447293186058619076878925484563950",
"253027930028827183023105043142239306135",
"182349311800086682754326787636114195725",
"96408791789250835426324001317292017638",
"21598914887812397469120839577458930658",
"176009772750833818285042273242439556533",
"37597691988822729530248010859717084786",
"73518832100609029311723363740203987172",
"328496809364413011490297103064268796662",
"92828448414571605246581151359962288970",
"144598832452975848378174692472097752632",
"30561734758201328948523025880147196956",
"153638216829489845942627450962622750547",
"184285594291065651895388878533203263133",
"400200632423164252003500010323705680",
"69168537644988749467834837735730248531",
"295669563967366483119228741242357988854",
"276469623951540531147430173908853796988"
]
},
"signature_version": "v1",
"source": "https://github.com/apache/hive/commit/45049202df35cea382616624de3fe8d252aa2d00",
"signature_type": "Line"
},
{
"id": "CVE-2026-55976-2d2113a9",
"target": {
"file": "ql/src/java/org/apache/hadoop/hive/ql/security/authorization/command/CommandAuthorizerV2.java"
},
"deprecated": false,
"digest": {
"threshold": 0.9,
"line_hashes": [
"177073787222309140716026921732488118573",
"51212544286892338670284227889950011564",
"323269922427506503459620292278458792534",
"94044514341491764747205505624578327224",
"286615194628137664358564849904063807197",
"292766396997965514710209969543099828229",
"246886177912563877088792418592977728875"
]
},
"signature_version": "v1",
"source": "https://github.com/apache/hive/commit/45049202df35cea382616624de3fe8d252aa2d00",
"signature_type": "Line"
},
{
"id": "CVE-2026-55976-4c053a42",
"target": {
"function": "noneOptionWorksForSpecifyingSchemas",
"file": "serde/src/test/org/apache/hadoop/hive/serde2/avro/TestAvroSerdeUtils.java"
},
"deprecated": false,
"digest": {
"function_hash": "90595563078112889883276071064837814349",
"length": 1296.0
},
"signature_version": "v1",
"source": "https://github.com/apache/hive/commit/45049202df35cea382616624de3fe8d252aa2d00",
"signature_type": "Function"
},
{
"id": "CVE-2026-55976-5d501e80",
"target": {
"file": "ql/src/java/org/apache/hadoop/hive/ql/security/authorization/plugin/metastore/events/CreateTableEvent.java"
},
"deprecated": false,
"digest": {
"threshold": 0.9,
"line_hashes": [
"190676620923053971001178513954202843398",
"284867498485529585933323131025606436897",
"145440475393030314487489402812996756137",
"257661294824368213224101056477144242380",
"149780884586875440714216291180729239946",
"273467310499391080980721605299053462674",
"238898122436587092572584911897810069197",
"127701381797069321766532513141795149080",
"170018064792176067034856105995677758683",
"59568427112801690802064408094330754898",
"38298172738520776296796549315642447495",
"101071456278239844677580827296422471340",
"157909550877745273027374687993133018195",
"185698172263534920829889527871163818808",
"7564459068491618906371208763920296999"
]
},
"signature_version": "v1",
"source": "https://github.com/apache/hive/commit/45049202df35cea382616624de3fe8d252aa2d00",
"signature_type": "Line"
},
{
"id": "CVE-2026-55976-6df9824d",
"target": {
"file": "ql/src/java/org/apache/hadoop/hive/ql/security/authorization/plugin/metastore/events/AlterTableEvent.java"
},
"deprecated": false,
"digest": {
"threshold": 0.9,
"line_hashes": [
"316518777327542083869712953984765073859",
"143582127901993582175385233640731788189",
"171285548016655874996363024873084836586",
"241412516770075555829302749150070788176",
"185293222830251530571252917243642719113",
"6448940372004451036852590684670553222",
"195396480031271048983216568473422115558",
"170877146177148643724924243186465070632",
"195407264460832617036980138417894646681",
"193345917868623610084355562357433201303"
]
},
"signature_version": "v1",
"source": "https://github.com/apache/hive/commit/45049202df35cea382616624de3fe8d252aa2d00",
"signature_type": "Line"
},
{
"id": "CVE-2026-55976-7646548a",
"target": {
"file": "serde/src/java/org/apache/hadoop/hive/serde2/avro/AvroSerdeUtils.java"
},
"deprecated": false,
"digest": {
"threshold": 0.9,
"line_hashes": [
"224685346072980477273160514245051899463",
"313234685655147340680440678908361852527",
"6351563200625745030231951506338008594",
"173259762935151701669749868498526600079",
"234660728165637300367904989005753466775",
"318995819177286634997240681533325943579",
"74495237253535940063739711831061186353",
"187864279256764458010626667829837239268",
"241095857647680142681022075301032025744",
"29788664511793123196087689897436818814",
"118561359119143193021371411138568620871",
"227984100261060317994806032541043926884",
"265397590830552778079482828519478496276",
"30018812252421920005220249921596521308",
"317322678509848851165748310764578921996",
"64928612850100657911363655673065375041",
"187268511372542181499894041768382887885",
"23912990718022068395242496793798527326",
"192172273082442485957854191938591227451",
"196476482374458010002806548455206527464",
"125898743872232138966501790851076221542"
]
},
"signature_version": "v1",
"source": "https://github.com/apache/hive/commit/45049202df35cea382616624de3fe8d252aa2d00",
"signature_type": "Line"
},
{
"id": "CVE-2026-55976-a2f5fd69",
"target": {
"function": "determineSchemaCanReadSchemaFromHDFS",
"file": "serde/src/test/org/apache/hadoop/hive/serde2/avro/TestAvroSerdeUtils.java"
},
"deprecated": false,
"digest": {
"function_hash": "278061159823255671167198307220604202731",
"length": 731.0
},
"signature_version": "v1",
"source": "https://github.com/apache/hive/commit/45049202df35cea382616624de3fe8d252aa2d00",
"signature_type": "Function"
},
{
"id": "CVE-2026-55976-a38ef2ee",
"target": {
"function": "getInputHObjs",
"file": "ql/src/java/org/apache/hadoop/hive/ql/security/authorization/plugin/metastore/events/CreateTableEvent.java"
},
"deprecated": false,
"digest": {
"function_hash": "279203210831975280791183659972074508396",
"length": 423.0
},
"signature_version": "v1",
"source": "https://github.com/apache/hive/commit/45049202df35cea382616624de3fe8d252aa2d00",
"signature_type": "Function"
},
{
"id": "CVE-2026-55976-c98469f6",
"target": {
"file": "serde/src/test/org/apache/hadoop/hive/serde2/avro/TestAvroSerdeUtils.java"
},
"deprecated": false,
"digest": {
"threshold": 0.9,
"line_hashes": [
"206293892291602054397469346148023758713",
"41443022427517934875436850295464337222",
"121916759495317661909586658456771621297",
"213476036740724275066765234435860788326",
"142036810634550671296873721204776563120",
"67617441303606952865831426442363407036",
"192014423770658741548208456619434165801",
"338465602926854783335655774855049245710",
"326667641658762595742685786185720250559",
"45582975196418983077348711004324338015",
"58961420402733140627300214926695599552",
"229783552858610189922489829637974350560",
"144071477525868946420704634947076404702",
"192571577669139393032502108145197091342",
"192274995385916781086286484954298111161",
"298970600623406877397975822634619562051",
"281677428009212153798713566410994701212",
"115219653218519079851154444582866045163",
"41661537399768891440479349359676269042",
"176530770225253488655595029250231661367",
"67178474168609796169392546833783944183",
"112736424213825883294915809691408234984",
"282177084689476153080346805261702300362",
"332447469099412546507715776115628123749",
"7723173095052504722326166108988722678",
"45103971623019589860882917707464479886",
"41661537399768891440479349359676269042",
"176530770225253488655595029250231661367",
"108651171038551102368863641550063024967",
"91503492950217224881219266254873425305",
"72214167744734663087783825233379493164",
"9757124218390018162713011042045465090"
]
},
"signature_version": "v1",
"source": "https://github.com/apache/hive/commit/45049202df35cea382616624de3fe8d252aa2d00",
"signature_type": "Line"
},
{
"id": "CVE-2026-55976-c997c276",
"target": {
"function": "addInput",
"file": "ql/src/java/org/apache/hadoop/hive/ql/plan/PlanUtils.java"
},
"deprecated": false,
"digest": {
"function_hash": "298495489266383426092005201270567878746",
"length": 573.0
},
"signature_version": "v1",
"source": "https://github.com/apache/hive/commit/45049202df35cea382616624de3fe8d252aa2d00",
"signature_type": "Function"
},
{
"id": "CVE-2026-55976-d1a875ee",
"target": {
"function": "determineSchemaTriesToOpenUrl",
"file": "serde/src/test/org/apache/hadoop/hive/serde2/avro/TestAvroSerdeUtils.java"
},
"deprecated": false,
"digest": {
"function_hash": "153459876566583443529357148674582294177",
"length": 439.0
},
"signature_version": "v1",
"source": "https://github.com/apache/hive/commit/45049202df35cea382616624de3fe8d252aa2d00",
"signature_type": "Function"
},
{
"id": "CVE-2026-55976-d505a595",
"target": {
"function": "getInputHObjs",
"file": "ql/src/java/org/apache/hadoop/hive/ql/security/authorization/plugin/metastore/events/AlterTableEvent.java"
},
"deprecated": false,
"digest": {
"function_hash": "249243013110332678812434371271621032350",
"length": 361.0
},
"signature_version": "v1",
"source": "https://github.com/apache/hive/commit/45049202df35cea382616624de3fe8d252aa2d00",
"signature_type": "Function"
},
{
"id": "CVE-2026-55976-eb21692d",
"target": {
"function": "determineSchemaOrThrowException",
"file": "serde/src/java/org/apache/hadoop/hive/serde2/avro/AvroSerdeUtils.java"
},
"deprecated": false,
"digest": {
"function_hash": "120139305095171854543485381710453113705",
"length": 1757.0
},
"signature_version": "v1",
"source": "https://github.com/apache/hive/commit/45049202df35cea382616624de3fe8d252aa2d00",
"signature_type": "Function"
},
{
"id": "CVE-2026-55976-f032e173",
"target": {
"file": "ql/src/java/org/apache/hadoop/hive/ql/plan/PlanUtils.java"
},
"deprecated": false,
"digest": {
"threshold": 0.9,
"line_hashes": [
"167131845950513518552775988318921545908",
"6094844128266943287703798366910539837",
"126960619812171496423757727914612924669",
"115390761114396432390318424359039029628",
"240698769879321137247772411386141069168",
"61326683224546590632214147595755933223",
"233476061422706967647629803865703859899",
"292947720883828695375063944735951992277"
]
},
"signature_version": "v1",
"source": "https://github.com/apache/hive/commit/45049202df35cea382616624de3fe8d252aa2d00",
"signature_type": "Line"
},
{
"id": "CVE-2026-55976-f43e8afb",
"target": {
"file": "ql/src/test/org/apache/hadoop/hive/ql/security/authorization/plugin/metastore/TestHiveMetaStoreAuthorizer.java"
},
"deprecated": false,
"digest": {
"threshold": 0.9,
"line_hashes": [
"337146747114281856239348121050379191032",
"87930461045209602344673616543196114065",
"20827637214583762821621698852996252754",
"75653543590221923608850445147617775958",
"263339922758720051178053149418986015954",
"291628373584856700625111656115775449911",
"85369437914636782960037472356668842065",
"75350660971816160154826349117637717036",
"135787286783381203056297635834455207281",
"129268417605416860353285595589078285117",
"125778081804519617440393513988335497697",
"209818205532550464619646497747393648933",
"266730743418499482633630281857504880855",
"185824224150428123532738203363982311254",
"303616638602982087414337967409902169955",
"24501234535006697431234705038672472381",
"71163166489256657315431930850110891718",
"63177220502634814975227272208566237680"
]
},
"signature_version": "v1",
"source": "https://github.com/apache/hive/commit/45049202df35cea382616624de3fe8d252aa2d00",
"signature_type": "Line"
},
{
"id": "CVE-2026-55976-fa83794f",
"target": {
"function": "getHivePrivilegeObjectsFromLastCall",
"file": "ql/src/test/org/apache/hadoop/hive/ql/security/authorization/plugin/metastore/TestHiveMetaStoreAuthorizer.java"
},
"deprecated": false,
"digest": {
"function_hash": "56701971473862277605576918577583134948",
"length": 474.0
},
"signature_version": "v1",
"source": "https://github.com/apache/hive/commit/45049202df35cea382616624de3fe8d252aa2d00",
"signature_type": "Function"
}
]
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-55976.json"
"2026-08-30T08:17:29Z"