oss-sec: CVE-2026-42810: Apache Polaris: Polaris accepts literal `*` characters in namespace and table names. When it later builds temporary S3 access policies for delegated table access, those same c

Read full story on seclists.org
oss-sec: CVE-2026-42810: Apache Polaris: Polaris accepts literal `*` characters in namespace and table names. When it later builds temporary S3 access policies for delegated table access, those same c

Summary

Severity: important Affected versions: - Apache Polaris before 1.4.1 Description: Apache Polaris accepts literal `*` characters in namespace and table names. Wh...

Original reporting

Open original source

AFBytes is a read-only aggregator. Use the original source for full context and complete reporting.

Related coverage

Read full article on seclists.org