Apache disclosed CVE-2026-41041, a low-severity vulnerability in Apache Gravitino caused by unencoded user-supplied identifiers in MCP REST client f-string URL construction. The flaw allows URL path injection that can lead to path traversal and access to unintended API endpoints, potentially altering how requests are routed within affected deployments.
The issue affects Apache Gravitino versions 1.0.0 through 1.2.0, with the fix released in version 1.2.1. The vulnerability was published through Apache and oss-security advisories, and users were urged to upgrade to Apache Gravitino 1.2.1 to remediate the issue.

See real exploitation activity before you spend the cycle.
2 events from the most recent confirmed update back to the earliest known activity.
On 2026-07-13, Apache disclosed CVE-2026-41041, a low-severity URL path injection vulnerability in Apache Gravitino. The flaw can allow path traversal to unintended API endpoints via unencoded user-supplied identifiers in MCP REST client URL construction.
Apache Gravitino version 1.2.1 was identified as the release that fixes a URL path injection flaw caused by unencoded user-supplied identifiers in MCP REST client f-string URL construction. The vulnerability affects versions 1.0.0 through versions before 1.2.1.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
5 references tracked. Mallory keeps watching after this page renders.
seclists.org
Open sourcelists.apache.org
Open sourceopenwall.com
Open sourcecve.org
Open sourcegravitino.apache.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.