CVE-2026-41041
Critical · CVSS 9.1Apache Gravitino — URL path injection via unencoded user-supplied identifiers
- CVSS
- 9.1
- nvd
- EPSS
- —
- KEV
- No
- Class
- other
- CWE-177
Description
URL path injection via unencoded user-supplied identifiers vulnerability in Apache Gravitino. This issue affects Apache Gravitino: from 1.0.0 before 1.2.1. Users are recommended to upgrade to version 1.2.1, which fixes the issue.
Search profile — drives PoC discovery
Symbols user-supplied identifiersURL path injectionunencoded identifierGravitino REST APIcatalog nameschema nametable name
Keywords CVE-2026-41041Apache GravitinoURL path injectionunencoded identifierCWE-177Gravitino 1.0.0Gravitino 1.2.1path injection Gravitino
Versions: 1.0.0 to before 1.2.1
References
Status: enriched · ingested 2026-07-14T00:00:21.000Z · profiled 2026-07-14T00:30:21.000Z