Junglewise Threat Intelligence

CVE-2026-41041: Apache Gravitino URL path injection via unencoded identifiers

CVE-2026-41041 · Severity: low · CVSS 3.1 · Published 2026-07-13

Technologies: Apache Software Foundation Gravitino. Vendors: PyPI, Apache, Apache Software Foundation.

Executive brief

Apache Gravitino, a high-performance metadata lake, is vulnerable to a security flaw where user-provided identifiers are not properly cleaned before being used in web addresses. This could allow an attacker to manipulate application requests, potentially leading to unauthorized access to data or unintended system behavior. Organizations should update to version 1.2.1 to resolve this issue.

Technical details

A URL path injection vulnerability exists in Apache Gravitino due to improper handling of URL encoding (CWE-177). The application fails to adequately encode user-supplied identifiers before incorporating them into URL paths. An attacker can exploit this by providing specially crafted identifiers containing path traversal or control characters, potentially allowing them to influence internal API calls or access unintended resources. This issue affects versions 1.0.0 through 1.2.0 and is resolved in version 1.2.1.

Affected products

  • Apache Gravitino 1.0.0 to 1.2.0

Timeline

  • 2026-07-13: disclosed
  • 2026-07-13: advisory

References

Related threats