CVE-2026-77810

Source
https://cve.org/CVERecord?id=CVE-2026-77810
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-77810.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-77810
Aliases
  • GHSA-v7c2-5wfg-qg44
Published
2026-08-21T19:34:06Z
Modified
2026-08-29T03:30:42Z
Severity
  • 9.4 (Critical) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H CVSS Calculator
Summary
Code Injection via Gremlin Query Passthrough in Amazon Athena Neptune Connector
Details

In the Neptune connector, a user with access to Neptune through Athena Federated Query could gain access to properties in the Lambda supplying the compute for the connector. To remediate this issue, users should upgrade to aws-athena-query-federation v2026.30.1 or later.

Database specific
{
    "cna_assigner": "AMZN",
    "cwe_ids": [
        "CWE-95"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/77xxx/CVE-2026-77810.json"
}
References

Affected packages

Git / github.com/awslabs/aws-athena-query-federation

Affected ranges

Type
GIT
Repo
https://github.com/awslabs/aws-athena-query-federation
Events
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "2024.15.1"
        },
        {
            "last_affected": "2026.28.1"
        }
    ],
    "source": [
        "AFFECTED_FIELD",
        "REFERENCES"
    ]
}

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-77810.json"