An issue exists in Amazon Redshift JDBC Driver versions prior to 2.2.2. Under certain conditions, the driver could load and execute arbitrary classes when processing JDBC connection URL parameters. An actor who can influence the connection URL could potentially execute code in the application context, provided a suitable class is available on the application's classpath.
To mitigate this issue, users should upgrade to version 2.2.2 or later.
{
"cna_assigner": "AMZN",
"cwe_ids": [
"CWE-470"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/8xxx/CVE-2026-8178.json"
}"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-8178.json"
[
{
"deprecated": false,
"digest": {
"line_hashes": [
"183276723764642442021227140030932784281",
"9980312845226736702786475975787273512",
"4176453312962318763630750899119976397",
"226576026871728754956374146957934770156",
"273514546383196571683608208248985371244"
],
"threshold": 0.9
},
"id": "CVE-2026-8178-4979b1a9",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/aws/amazon-redshift-jdbc-driver/commit/f8b5e0f053a981927db49acec24b920cb856909c",
"target": {
"file": "src/main/java/com/amazon/redshift/RedshiftConnection.java"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "20707112758364468040286501724160506610",
"length": 939
},
"id": "CVE-2026-8178-739fe9c1",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/aws/amazon-redshift-jdbc-driver/commit/f8b5e0f053a981927db49acec24b920cb856909c",
"target": {
"file": "src/main/java/com/amazon/redshift/jdbc/RedshiftConnectionImpl.java",
"function": "initObjectTypes"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"52297638782907272979842749224619786390",
"160842460070240797211085196988420667002",
"9671264503837736572467963858286390699",
"260595862865047996994698455150338319852",
"282692241412697938604064891112196524457",
"28620959763911048160910946459708332584",
"160498221485947594109322409499126934363",
"325775753760943537541569776384817819771",
"129609646341157626827423945432751566545",
"91482742935047240390675657741913663379",
"235800656643896860974692691293601870819",
"78293847051598451915352461859310639904",
"267436712134870115377913356756503165101",
"306709787135194044968745497579243793965",
"1510027037419087856044684384726847722",
"213499349901938574263571821072303562237",
"70327141548093956636747432840608508705",
"66610313417162716917280507647330864604",
"29560952656319937798333834318373512946",
"147054910802966217585420791302883002976",
"212845755112452731899559235981184601810",
"117178324811345819613454800425411037488",
"221597630475594385213942203222806086374",
"190173751563160178162598028236363859089",
"179180044336854412868254409018693838984",
"37479557905076896909582040427104569854",
"160116554069429921170229220967817098592",
"152485229798325412973069973077152851103",
"86641019051466830419135969501268581415",
"307424545829671304077245756947992946363",
"295747577431459138783214723720080232905",
"328550155374325234943634329962723945114"
],
"threshold": 0.9
},
"id": "CVE-2026-8178-9e823680",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/aws/amazon-redshift-jdbc-driver/commit/f8b5e0f053a981927db49acec24b920cb856909c",
"target": {
"file": "src/main/java/com/amazon/redshift/jdbc/RedshiftConnectionImpl.java"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "62081695060000825474947310952719264919",
"length": 219
},
"id": "CVE-2026-8178-dfe95efc",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/aws/amazon-redshift-jdbc-driver/commit/f8b5e0f053a981927db49acec24b920cb856909c",
"target": {
"file": "src/main/java/com/amazon/redshift/jdbc/RedshiftConnectionImpl.java",
"function": "addDataType"
}
}
]
"2026-08-12T16:09:23Z"