CVE-2026-65321
Wstrzyknięcie SQL w PyAthena umożliwia nieautoryzowanym atakującym wyciek danych i wykonanie destrukcyjnych poleceń.
PyAthena prior to 3.35.4 contains a sql injection vulnerability that allows unauthenticated attackers to inject arbitrary SQL by exploiting improper quote-escaping in DefaultParameterFormatter.format(), which routes DELETE and CTAS statements to the _escape_hive function that backslash-escapes single quotes rather than doubling them. Because Athena and Trino do not treat backslashes as escape characters inside string literals, attacker-supplied input such as a single quote followed by SQL syntax causes the parser to terminate the string literal prematurely, enabling data exfiltration via UNION SELECT, execution of destructive statements, and attacker-controlled CTAS destination and content.
| Źródło | Wartość |
|---|---|
| NVD – CVSS | 9.8 |
| CISA KEV (aktywnie wykorzystywane) | Nie |
| FIRST EPSS (prawdopodobieństwo exploita) | 0.5% |
| Opublikowano (NVD) | 2026-08-02 15:16:33 UTC |
| Ostatnia modyfikacja (NVD) | 2026-08-06 22:18:14 UTC |
- https://github.com/laughingman7743/PyAthena (disclosure@vulncheck.com)
- https://github.com/laughingman7743/PyAthena/security/advisories/GHSA-xwj5-g6cv-4r5c (disclosure@vulncheck.com)
- https://github.com/pyathena-dev/PyAthena/commit/27901d12245ea722b3b4e211c60e2ade4e7c8efd (disclosure@vulncheck.com)
- https://github.com/rahulreddykarne/CVE-2026-65321-pyathena (disclosure@vulncheck.com)
- https://rahulkarne.com/#/cve/CVE-2026-65321 (disclosure@vulncheck.com)
- https://www.vulncheck.com/advisories/pyathena-sql-injection-via-defaultparameterformatter-delete-ctas (disclosure@vulncheck.com)