Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.1
CVE-2026-41041: Apache Gravitino: Malicious URLs Can Access Sensitive API Data
CVE-2026-41041 · published 2 months ago
Summary
Apache Gravitino's MCP REST client fails to properly encode user input in URLs, potentially allowing attackers to access sensitive data or API endpoints. This vulnerability affects all versions of Apache Gravitino prior to 1.2.1. To fix this issue, users should upgrade to version 1.2.1.
What to do
- Update apache software foundation apache gravitino to version 1.2.1 or later.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| apache software foundation | apache gravitino | < 1.2.1 |
Original advisory text
URL path injection via unencoded user-supplied identifiers vulnerability in Apache Gravitino.
This issue affects Apache Gravitino: from 1.0.0 before 1.2.1.
Users are recommended to upgrade to ver...
URL path injection via unencoded user-supplied identifiers vulnerability in Apache Gravitino.
This issue affects Apache Gravitino: from 1.0.0 before 1.2.1.
Users are recommended to upgrade to version 1.2.1, which fixes the issue.
This issue affects Apache Gravitino: from 1.0.0 before 1.2.1.
Users are recommended to upgrade to version 1.2.1, which fixes the issue.
Severity
9.1
Critical
Exploitation
EPSS <1%
Type
CWE-177Improper Handling of URL Encoding (Hex Encoding)
Timeline
Published13 Jul 2026
Updated25 Sep 2026
First seen13 Jul 2026
Track software like this
Free during beta