Apache disclosed CVE-2026-42812, an important-severity vulnerability in Apache Polaris before 1.4.1 that fails to enforce validation on the write.metadata.path table property during certain ALTER TABLE-style updates. By changing only that property, a user can cause Polaris to write Apache Iceberg table metadata to an attacker-chosen reachable storage location instead of the intended validated path.
In deployments where polaris.config.allow.unstructured.table.location=true and allowedLocations is broadly configured, the malicious path can be saved and later used by table-load and credential APIs to obtain temporary cloud-storage credentials for that same location without revalidation. Apache warned this can expose or enable modification, corruption, or deletion of data and metadata beyond the targeted table, potentially affecting other prefixes or even bucket or container roots depending on configuration and provider behavior; the underlying validation bypass still exists even when unstructured table locations are disabled, though later checks may prevent the unsafe path from being persisted.

See affected versions and whether adversaries are exploiting it.
3 events from the most recent confirmed update back to the earliest known activity.
Apache released HTTP Server version 2.4.67 to remediate CVE-2026-33523, with the fix tracked in the 2.4.x branch as revision r1933360. This addressed the response splitting issue in affected modules present in versions 2.4.0 through 2.4.66.
Apache disclosed CVE-2026-42812, an important-severity vulnerability in Apache Polaris before version 1.4.1 involving insufficient validation of the `write.metadata.path` table property. The flaw can let metadata be written to attacker-chosen storage locations and, in some configurations, expose temporary cloud-storage credentials for broader storage paths.
Apache recorded CVE-2026-33523, a low-severity HTTP response splitting flaw affecting Apache HTTP Server 2.4.0 through 2.4.66 when forwarding a malicious status line from untrusted or compromised backend servers. The issue was reported on 2026-03-05, and Apache credited Haruki Oyama of Waseda University, Merih Mengisteab, and Dawit Jeong with finding it.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
3 references tracked. Mallory keeps watching after this page renders.
cvefeed.io
Open sourceseclists.org
Open sourceseclists.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.