PoC Archive PoC Archive

tag

CWE-441

  • CVE-2026-64640 cloud HIGH 8.1

    Apache Polaris — Cross-Tenant Credential Vending Before Location Validation in Iceberg REST Register (CVE-2026-64640)

    CVE-2026-64640 is a confused-deputy vulnerability in Apache Polaris: the Iceberg REST register endpoints mint cloud storage credentials for a caller-supplied path and read that path server-side before checking it against the catalog's allowedLocations. A…

    Patched 2026-08-09