Skip to content

2.1.1 Fixed vulnerabilities CVE-2026-73334, CVE-2026-87795, CVE-2026-87823, CVE-2026-89045

Latest

Choose a tag to compare

@github-actions github-actions released this 15 Sep 15:16
1645040

This release fixes the following 4 vulnerabilities:

Warning: CVE-2026-90559 in org.xerial.snappy:snappy-java:1.1.10.8

Snappy remains supported for compatibility, but the transitive Snappy-Java dependency has an unresolved native out-of-bounds write vulnerability. A malicious Snappy-compressed Parquet file can terminate the JVM. Process only trusted Snappy files or isolate their processing until an upstream fix is available.

CVE-2026-73334 (CWE-20) in dependency org.apache.parquet:parquet-hadoop:jar:1.17.1:compile

Potential problem for users of the org.apache.parquet.crypto.keytools package in Apache Parquet, versions 1.12 to 1.18.
This package enables users to encrypt Parquet files via an envelope encryption mechanism that wraps (encrypts) data keys via a Key Management Service (KMS). 
On the reader side, the KMS URL can be application-controlled or file-controlled.
If the user does not leverage application control for this parameter, a file-controlled KMS URL is forwarded to a pluggable KmsClient implementation.
If the pluggable implementation does not perform host validation, a KMS token can be sent to a malicious host set by an attacker in the file.

Before the problem is fixed, users are recommended to leverage application control for KMS URL parameter in readers (versions 1.12-1.18).
After the problem is fixed (presumably in version 1.19), the upgrade will disable file-controlled KMS URL by default. Users of the KMS URL parameter 
will have two options then: leverage application control for KMS URL parameter in readers, or enable file-controlled KMS URL (via a new app parameter).
The latter option will explicitly require (in the new parameter documentation) to validate the KMS URL and use authentication in the custom implementation of the KMS client plug in.

References

CVE-2026-87795 (CWE-125) in dependency com.github.luben:zstd-jni:jar:1.5.7-3:compile

zstd-jni versions before 1.5.7-14 fail to validate offset and length parameters in the ZstdDictCompress constructor, allowing out-of-bounds memory reads. Attackers can supply untrusted offset or length values to read native heap memory into the compression dictionary, typically causing JVM crashes.

References

CVE-2026-87823 (CWE-190) in dependency com.github.luben:zstd-jni:jar:1.5.7-3:compile

zstd-jni before 1.5.7-14 performs 32-bit signed bounds checks on three direct-ByteBuffer frame-size native methods, allowing out-of-bounds memory reads via negative or overflowing offsets. Attackers can supply negative offset values near Integer.MIN_VALUE to read unmapped memory, causing JVM termination or extracting arbitrary frame size data from unintended memory locations.

References

CVE-2026-89045 (CWE-835) in dependency com.github.luben:zstd-jni:jar:1.5.7-3:compile

zstd-jni versions 1.4.8-4 through 1.5.7-13 fail to validate negative length parameters in ZstdInputStreamNoFinalizer.read(), allowing attackers to trigger infinite loops. Attackers can pass negative length values to cause the read method to spin indefinitely while holding the stream monitor, blocking all other threads from accessing the stream.

References

Security

  • #97: Fixed vulnerability CVE-2026-73334 in dependency org.apache.parquet:parquet-hadoop:jar:1.17.1:compile
  • #98: Fixed vulnerability CVE-2026-87795 in dependency com.github.luben:zstd-jni:jar:1.5.7-3:compile
  • #99: Fixed vulnerability CVE-2026-87823 in dependency com.github.luben:zstd-jni:jar:1.5.7-3:compile
  • #100: Fixed vulnerability CVE-2026-89045 in dependency com.github.luben:zstd-jni:jar:1.5.7-3:compile

Dependency Updates

Compile Dependency Updates

  • Updated org.apache.parquet:parquet-hadoop:1.17.1 to 1.18.1

Runtime Dependency Updates

  • Updated org.slf4j:jcl-over-slf4j:2.0.18 to 2.0.19

Test Dependency Updates

  • Updated org.slf4j:slf4j-jdk14:2.0.18 to 2.0.19

Plugin Dependency Updates

  • Updated com.exasol:error-code-crawler-maven-plugin:2.1.0 to 2.1.1
  • Updated com.exasol:project-keeper-maven-plugin:5.7.4 to 5.7.5
  • Updated io.github.git-commit-id:git-commit-id-maven-plugin:10.0.0 to 10.0.1
  • Updated org.apache.maven.plugins:maven-toolchains-plugin:3.2.0 to 3.3.0
  • Updated org.codehaus.mojo:flatten-maven-plugin:1.7.3 to 1.8.0
  • Updated org.itsallcode:openfasttrace-maven-plugin:2.3.0 to 3.0.0