freenode
Security & Cryptography

Apache Polaris lets table writers redirect server storage traffic

CVE-2026-97395 affects Polaris before 1.8.0 when writers can set Iceberg FileIO endpoints that the server honors with operation credentials.

Apache Polaris versions before 1.8.0 contain an important flaw, CVE-2026-97395, that lets an authenticated user who can create or update Iceberg table properties steer server-side storage traffic to a host they choose.

Polaris accepted FileIO client settings such as an S3 endpoint from table metadata. During server-side Iceberg work (commits and purges), it could build its own FileIO client from those settings. If the catalog storage configuration did not override the endpoint, Polaris sent storage requests to the writer-supplied host and attached credentials scoped to the operation. That redirects server-side storage traffic and can expose request authentication material to an attacker-controlled endpoint.

Deployments are at risk when table writers are not fully trusted to configure server-side storage endpoints. The issue was reported by vignesh a. Users should upgrade to Apache Polaris 1.8.0 or later.