← Advisories

Apache Avatica 1.29.0 JDBC Connection Property Injection

Medium
Advisory ID
ZSL-2026-6013
Release Date
08 October 2026
Vendor
The Apache Software Foundation - https://www.apache.org
Affected Version
1.29.0 and 1.28.0
CVE
N/A
Tested On
Eclipse Temurin OpenJDK 21.0.6 (LTS), avatica-server 1.28.0
Summary

Avatica is a framework for building database drivers. Avatica is defined by a wire API between a client and a server. The Avatica server is an HTTP server, the Avatica client is a JDBC driver, and the wire API is defined by JSON or Protobuf Buffers. The flexibility of the wire API and HTTP transport allows other Avatica clients to be built in any language, implementing any client specification. Avatica is a sub-project of the Apache Calcite project.

Description

Apache Calcite Avatica (avatica-server) copies client-supplied JDBC connection properties into the backend connection with no filtering by default (JdbcMeta.openConnection: fullInfo.putAll(info) then DriverManager.getConnection), and authentication is disabled by default, so an unauthenticated remote client can inject driver properties such as allowLoadLocalInfile or autoDeserialize.

The backend JDBC URL itself is fixed by the operator, so the injected properties only produce impact against a backend that is attacker-controlled or reachable via man-in-the-middle: in that case allowLoadLocalInfile can make the backend read local files from the Avatica host (disclosure), and autoDeserialize can cause deserialization of attacker data, which becomes remote code execution only when a suitable gadget is present on the backend classpath.

// avatica-server JdbcMeta.java:611-617 @Override public void openConnection(ConnectionHandle ch, Map<String, String> info) { Properties fullInfo = new Properties(); fullInfo.putAll(this.info); if (info != null) { fullInfo.putAll(info); // <-- client-controlled props, merged with no filtering } ... Connection conn = createConnection(url, fullInfo); } // JdbcMeta.java:638-640 protected Connection createConnection(String url, Properties info) throws SQLException { return DriverManager.getConnection(url, info); // <-- attacker props reach the backend JDBC driver }
Proof of Concept
Disclosure Timeline
13.08.2026Vulnerability discovered.
18.08.2026Contact with the vendor.
19.08.2026Vendor forwards details to appropriate PMC.
20.08.2026Vendor will review the details.
25.08.2026Vendor decided to not consider this as a security vulnerability.
25.08.2026Replied to the vendor.
25.08.2026Vendor releases improvement ticket CALCITE-7745.
08.10.2026Public security advisory released.
Credits
Vulnerability discovered by Gjoko Krstic
References
Changelog
08.10.2026Initial release