Apache Hive
Apache Software Foundation- Product type
- Other
- Catalog vulnerabilities
- 18
Severity across 18 analyzed records
Verify to analyze this security profile
en
Severity across 18 analyzed records
Verify to analyze this security profile
As of 09/14/2026, within CyStack's analyzed data, Apache Hive has 3 security vulnerabilities published in the last 90 days. Of these, 3 are rated High or Critical. None of these vulnerabilities is listed in the CISA KEV catalog. CyStack recommends that organizations and individual users remediate applicable vulnerabilities as soon as possible.
CyStack does not yet have sufficient official-source data to identify the latest version of Apache Hive and determine which vulnerabilities affect that version.
CyStack VulnScan continuously discovers assets, validates vulnerabilities, and helps security teams prioritize remediation across the organization.
Explore CyStack VulnScan| Vulnerability | Exploitation status | Fix | Published | Severity |
|---|---|---|---|---|
CVE-2026-49845Apache Hive: SQL Injection vulnerability in HiveMetaStore partition-name direct-SQL paths | Exploitation statusNot known exploited | FixYes | Published08/25/2026 | SeverityCritical |
CVE-2026-55976Apache Hive: SSRF vulnerability in Hive Avro Serde due to Insufficient input validation on avro.schema.url | Exploitation statusNot known exploited | FixYes | Published08/25/2026 | SeverityCritical |
CVE-2026-53561Apache Hive: Unauthenticated authentication bypass in HiveServer2 HTTP SAML bearer-token validation allows impersonation of any Hive user | Exploitation statusNot known exploited | FixYes | Published08/25/2026 | SeverityHigh |
CVE-2025-62728Apache Hive: SQL injection vulnerability when processing delete column statistics requests via the HMS Thrift APIs | Exploitation statusNot known exploited | FixYes | Published11/26/2025 | SeverityMedium |
CVE-2024-29869Apache Hive: Credentials file created with non restrictive permissions | Exploitation statusNot known exploited | FixYes | Published01/28/2025 | SeverityMedium |
CVE-2024-23953Apache Hive: Timing Attack Against Signature in LLAP util | Exploitation statusNot known exploited | FixYes | Published01/28/2025 | SeverityMedium |
CVE-2024-23945Apache Hive, Apache Spark, Apache Spark: CookieSigner exposes the correct signature when message verification fails | Exploitation statusNot known exploited | FixYes | Published12/23/2024 | SeverityMedium |
CVE-2022-41137Apache Hive: Deserialization of untrusted data when fetching partitions from the Metastore | Exploitation statusNot known exploited | FixYes | Published12/05/2024 | SeverityHigh |
CVE-2023-35701Apache Hive: Arbitrary command execution via JDBC driver | Exploitation statusNot known exploited | FixYes | Published05/03/2024 | SeverityMedium |
CVE-2021-34538Apache Hive Security vulnerability in Hive with UDFs | Exploitation statusNot confirmed | FixYes | Published07/16/2022 | SeverityUnknown |
CVE-2020-1926Timing attack in Cookie signature verification | Exploitation statusNot confirmed | FixYes | Published03/16/2021 | SeverityUnknown |
CVE-2018-11777 | Exploitation statusNot confirmed | FixNot confirmed | Published11/08/2018 | SeverityUnknown |
CVE-2018-1314 | Exploitation statusNot confirmed | FixNot confirmed | Published11/08/2018 | SeverityUnknown |
CVE-2018-1315 | Exploitation statusNot confirmed | FixNot confirmed | Published04/05/2018 | SeverityUnknown |
CVE-2018-1284 | Exploitation statusNot confirmed | FixNot confirmed | Published04/05/2018 | SeverityUnknown |
CVE-2018-1282 | Exploitation statusNot confirmed | FixNot confirmed | Published04/05/2018 | SeverityUnknown |
CVE-2017-12625 | Exploitation statusNot confirmed | FixNot confirmed | Published11/01/2017 | SeverityUnknown |
CVE-2016-3083 | Exploitation statusNot confirmed | FixNot confirmed | Published05/30/2017 | SeverityUnknown |