logo

Critical RCE Flaw in Apache Flink (CVE-2026-35194) Threatens TaskManagers

ID: 5c815354-02bf-5038-8a3b-f178b626111e

STIX ID: report--5c815354-02bf-5038-8a3b-f178b626111e

Feed Name: securityonline.info

Threat Score
75/100

Date Published: 2026-05-18

Date Updated: 2026-05-18

Author: Ddos

...
...

A critical SQL injection vulnerability (CVE-2026-35194) in Apache Flink's code generation process allows authenticated users with query submission privileges to inject arbitrary Java expressions, enabling remote code execution on TaskManagers. The flaw stems from inadequate escaping of user-controlled strings in JSON functions (>=1.15.0) and LIKE expressions with ESCAPE clauses (>=1.17.0), affecting Flink 1.15.0–1.20.x and 2.0.0–2.x; maintainers released patches and recommend upgrading to 1.20.4, 2.0.2, 2.1.2, or 2.2.1.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.