Severity: important 

Affected versions:

- Apache Polaris before 1.8.0

Description:

Apache Polaris allows an authenticated principal with permission to create or 
update Iceberg table properties to set FileIO client settings such as 
s3.endpoint in table metadata.


In versions < 1.8.0, when Polaris performs server-side Iceberg operations, 
including commits and purges, it may use those settings to construct its 
(server-side) FileIO client. If the catalog storage configuration does not 
override the endpoint, Polaris can send storage requests to a host chosen by 
the table writer, using credentials scoped to the operation.




This can redirect server-side storage traffic and expose request authentication 
material to the chosen endpoint. Deployments are affected when table writers 
are not trusted to configure server-side storage endpoints.

Credit:

vignesh a <[email protected]> (reporter)

References:

https://polaris.apache.org
https://www.cve.org/CVERecord?id=CVE-2026-97395

Reply via email to