Junglewise Threat Intelligence

CVE-2026-65321: PyAthena SQL injection in DefaultParameterFormatter

CVE-2026-65321 · Severity: critical · CVSS 9.8 · Published 2026-08-02

Executive brief

PyAthena is a Python database client for Amazon Athena that allows applications to parameterize SQL queries securely. A flaw in the parameter formatting logic fails to properly escape single quotes in DELETE and CREATE TABLE AS SELECT statements, allowing unauthenticated attackers to inject arbitrary SQL. This can lead to unauthorized data access, modification of tables, or execution of destructive queries—a complete compromise of database security.

Technical details

This SQL injection vulnerability (CWE-89) exists in PyAthena's DefaultParameterFormatter.format() method, which uses incorrect quote-escaping for DELETE and CTAS (CREATE TABLE ... AS SELECT) statements. The vulnerable code routes these statement types through _escape_hive(), which backslash-escapes single quotes ('' → \'), whereas Athena and Trino do not treat backslashes as escape characters inside string literals. Unauthenticated attackers can inject SQL by supplying parameter values containing a single quote followed by SQL syntax (e.g., a' OR 1=1 --), which terminates the string literal prematurely and exposes the remaining text as executable SQL. An attacker can exfiltrate data via UNION SELECT, execute destructive statements, or control CTAS destination and content. The fix is available in version 3.35.4, which routes all statement types through the Trino-safe _escape_presto() escaper that doubles quotes (' → '').

Affected products

  • PyAthena PyAthena <3.35.4

Timeline

  • 2026-07-31: disclosed
  • 2026-08-02: patched: Fixed in version 3.35.4
  • 2026-08-02: advisory

References