CVE-2026-97395: Apache Polaris: Allows authorized table writers to redirect server-side Iceberg FileIO requests to attacker-controlled endpoints using operation-scoped storage credentials
Apache Polaris allows an authenticated principal with permission to create or update Iceberg table properties to set FileIO client settings such as s3.endpoint in table metadata.
In versions < 1.8.0, when Polaris performs server-side Iceberg operations, including commits and purges, it may use those settings to construct its (server-side) FileIO client. If the catalog storage configuration does not override the endpoint, Polaris can send storage requests to a host chosen by the table writer, using credentials scoped to the operation.
This can redirect server-side storage traffic and expose request authentication material to the chosen endpoint. Deployments are affected when table writers are not trusted to configure server-side storage endpoints.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Apache Polaristo a version that resolves this vulnerability.Fixed in 1.8.0 - Configuration
Configure the catalog storage configuration to override the endpoint so table writers cannot redirect server-side Iceberg FileIO requests.
Apache Polaris catalog storage configuration storage endpoint override = override the table-provided endpoint
Event History
Frequently Asked Questions
Which deployments are exposed to this issue?
Deployments are affected when authenticated users who can create or update Iceberg table properties are not trusted to configure server-side storage endpoints. The catalog storage configuration must also not override the endpoint selected through table metadata.
What level of access does an attacker need?
An attacker needs to be an authenticated principal with permission to create or update Iceberg table properties. They can set FileIO client settings, such as s3.endpoint, in table metadata.
What can the attacker redirect, and what could be exposed?
During server-side Iceberg operations such as commits and purges, Polaris may send storage requests to an attacker-controlled host. Those requests can include authentication material from credentials scoped to the operation.
Are deployments protected if the catalog storage configuration sets an endpoint?
The described redirection occurs when the catalog storage configuration does not override the endpoint. Configuring the catalog to override the endpoint prevents table metadata from selecting the endpoint used for these server-side storage requests.