UNKNOWNPyPI

Apache Polaris did not consistently validate storage locations supplied during table and view registration. An authenti

Apache Polaris did not consistently validate storage locations supplied during table and view registration. An authenticated principal with permission to register a table or view could, depending on the affected release and registration path, cause Polaris to use the catalog's storage credentials to read a caller-selected Iceberg metadata file before verifying that the file was within the catalog's allowed storage locations. If the catalog's underlying credentials could read an object outside 

CVE-2026-64640Published 2 weeks agoUpdated 2 weeks agoSource: OSV

Affected packages

  • apache-polarisbefore 1.7.0

Exploit signal

Known exploited (CISA KEV)
No
EPSS score
EPSS percentile

EPSS is the probability a CVE is exploited in the wild; percentile is its rank among all CVEs.