CLEANSTART-2026-QP89146
Dashboard / Vulnerabilities / CLEANSTART-2026-QP89146
CLEANSTART-2026-QP89146
Summary: Improper Control of Generation of Code ('Code Injection') vulnerability in Apache Avro Java SDK when generating specific records from untrusted Avro schemas
Details: Multiple security vulnerabilities affect the apache-hive package. Improper Control of Generation of Code ('Code Injection') vulnerability in Apache Avro Java SDK when generating specific records from untrusted Avro schemas. See references for individual vulnerability details.
References: https://github.com/cleanstart-dev/cleanstart-security-advisories/tree/main/advisories/2026/CLEANSTART-2026-QP89146.json, https://osv.dev/vulnerability/CVE-2025-33042, https://osv.dev/vulnerability/CVE-2025-41242, https://osv.dev/vulnerability/CVE-2025-55163, https://osv.dev/vulnerability/CVE-2025-59250, https://osv.dev/vulnerability/CVE-2025-62728, https://osv.dev/vulnerability/CVE-2026-12185, https://osv.dev/vulnerability/CVE-2026-22745, https://osv.dev/vulnerability/CVE-2026-40563, https://osv.dev/vulnerability/CVE-2026-41603, https://osv.dev/vulnerability/CVE-2026-41720, https://osv.dev/vulnerability/CVE-2026-41848, https://osv.dev/vulnerability/CVE-2026-41850, https://osv.dev/vulnerability/CVE-2026-41851, https://osv.dev/vulnerability/CVE-2026-41852, https://osv.dev/vulnerability/CVE-2026-43869, https://osv.dev/vulnerability/CVE-2026-45292, https://osv.dev/vulnerability/CVE-2026-49844, https://osv.dev/vulnerability/CVE-2026-50193, https://osv.dev/vulnerability/CVE-2026-54512, https://osv.dev/vulnerability/CVE-2026-54513, https://osv.dev/vulnerability/CVE-2026-54514, https://osv.dev/vulnerability/CVE-2026-54515, https://osv.dev/vulnerability/CVE-2026-55851, https://osv.dev/vulnerability/CVE-2026-57914, https://osv.dev/vulnerability/CVE-2026-59639, https://osv.dev/vulnerability/CVE-2026-59642, https://osv.dev/vulnerability/CVE-2026-59645, https://osv.dev/vulnerability/CVE-2026-59647, https://osv.dev/vulnerability/CVE-2026-59650, https://osv.dev/vulnerability/CVE-2026-59651, https://osv.dev/vulnerability/CVE-2026-59889, https://osv.dev/vulnerability/CVE-2026-59901, https://osv.dev/vulnerability/CVE-2026-59919, https://osv.dev/vulnerability/CVE-2026-8763, https://osv.dev/vulnerability/ghsa-2r2c-cx56-8933, https://osv.dev/vulnerability/ghsa-47qp-hqvx-6r3f, https://osv.dev/vulnerability/ghsa-mhm7-754m-9p8w, https://osv.dev/vulnerability/ghsa-r7wm-3cxj-wff9, https://nvd.nist.gov/vuln/detail/CVE-2025-33042, https://nvd.nist.gov/vuln/detail/CVE-2025-41242, https://nvd.nist.gov/vuln/detail/CVE-2025-55163, https://nvd.nist.gov/vuln/detail/CVE-2025-59250, https://nvd.nist.gov/vuln/detail/CVE-2025-62728, https://nvd.nist.gov/vuln/detail/CVE-2026-12185, https://nvd.nist.gov/vuln/detail/CVE-2026-22745, https://nvd.nist.gov/vuln/detail/CVE-2026-40563, https://nvd.nist.gov/vuln/detail/CVE-2026-41603, https://nvd.nist.gov/vuln/detail/CVE-2026-41720, https://nvd.nist.gov/vuln/detail/CVE-2026-41848, https://nvd.nist.gov/vuln/detail/CVE-2026-41850, https://nvd.nist.gov/vuln/detail/CVE-2026-41851, https://nvd.nist.gov/vuln/detail/CVE-2026-41852, https://nvd.nist.gov/vuln/detail/CVE-2026-43869, https://nvd.nist.gov/vuln/detail/CVE-2026-45292, https://nvd.nist.gov/vuln/detail/CVE-2026-49844, https://nvd.nist.gov/vuln/detail/CVE-2026-50193, https://nvd.nist.gov/vuln/detail/CVE-2026-54512, https://nvd.nist.gov/vuln/detail/CVE-2026-54513, https://nvd.nist.gov/vuln/detail/CVE-2026-54514, https://nvd.nist.gov/vuln/detail/CVE-2026-54515, https://nvd.nist.gov/vuln/detail/CVE-2026-55851, https://nvd.nist.gov/vuln/detail/CVE-2026-57914, https://nvd.nist.gov/vuln/detail/CVE-2026-59639, https://nvd.nist.gov/vuln/detail/CVE-2026-59642, https://nvd.nist.gov/vuln/detail/CVE-2026-59645, https://nvd.nist.gov/vuln/detail/CVE-2026-59647, https://nvd.nist.gov/vuln/detail/CVE-2026-59650, https://nvd.nist.gov/vuln/detail/CVE-2026-59651, https://nvd.nist.gov/vuln/detail/CVE-2026-59889, https://nvd.nist.gov/vuln/detail/CVE-2026-59901, https://nvd.nist.gov/vuln/detail/CVE-2026-59919, https://nvd.nist.gov/vuln/detail/CVE-2026-8763
Affected packages
Package
Name: apache-hive
Purl:
Affected ranges
Type: ECOSYSTEM
Events:
