Critical RCE Flaw in Apache Flink (CVE-2026-35194) Threatens TaskManagers
ID: 5c815354-02bf-5038-8a3b-f178b626111e
STIX ID: report--5c815354-02bf-5038-8a3b-f178b626111e
Feed Name: securityonline.info
A critical SQL injection vulnerability (CVE-2026-35194) in Apache Flink's code generation process allows authenticated users with query submission privileges to inject arbitrary Java expressions, enabling remote code execution on TaskManagers. The flaw stems from inadequate escaping of user-controlled strings in JSON functions (>=1.15.0) and LIKE expressions with ESCAPE clauses (>=1.17.0), affecting Flink 1.15.0–1.20.x and 2.0.0–2.x; maintainers released patches and recommend upgrading to 1.20.4, 2.0.2, 2.1.2, or 2.2.1.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
