---------- Forwarded message ---------
From: Sai Hemanth Gantasala <[email protected]>
Date: Mon, Aug 24, 2026 at 12:27 PM
Subject: [ANNOUNCE] Apache Hive 4.2.1 Released
To: <[email protected]>, dev <[email protected]>, <[email protected]>


The Apache Hive team is proud to announce the release of Apache Hive
version 4.2.1.

This bugfix release addresses three security vulnerabilities:

HIVE-29622: Potential vulnerability in HiveMetaStore partition-name
direct-SQL paths
HIVE-29653: Unauthenticated authentication bypass in HiveServer2 HTTP
SAML bearer-token validation
HIVE-29671: SSRF in Avro SerDe via avro.schema.url

Users running Apache Hive 4.2.0 are encouraged to upgrade to 4.2.1.

The Apache Hive (TM) data warehouse software facilitates querying and
managing large datasets residing in distributed storage. Built on top
of Apache Hadoop (TM), it provides, among others:

Tools to enable easy data extract/transform/load (ETL)
A mechanism to impose structure on a variety of data formats
Access to files stored either directly in Apache HDFS (TM) or in other
data storage systems such as Apache HBase (TM)
Massively parallel query execution via Apache Tez

For Hive release details and downloads, please visit:
https://hive.apache.org/downloads.html

Hive 4.2.1 Release Notes are available here:
https://issues.apache.org/jira/secure/ReleaseNote.jspa?projectId=12310843&version=12357270

For the Docker image, check:
https://hub.docker.com/r/apache/hive/tags

We would like to thank the many contributors who made this release possible.

Regards,
The Apache Hive Team

Reply via email to