{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/products/pyathena--3.35.4/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":9.8,"id":"CVE-2026-65321"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["PyAthena (\u003c 3.35.4)"],"_cs_severities":["critical"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":[],"content_html":"\u003cp\u003ePyAthena versions prior to 3.35.4 contain a critical SQL injection vulnerability originating from the DefaultParameterFormatter.format() method. The issue resides in the _escape_hive function, which incorrectly attempts to escape single quotes using backslashes. Because the underlying Athena and Trino SQL engines do not recognize backslashes as valid escape characters for string literals, the use of a single quote in user-supplied input allows an attacker to prematurely terminate a string literal. This flaw enables the injection of arbitrary SQL commands, potentially leading to unauthorized data exfiltration via UNION SELECT queries, execution of destructive administrative commands, or modification of CTAS (Create Table As Select) operations to point to attacker-controlled destinations. This vulnerability impacts all applications utilizing PyAthena as a connector for Athena or Trino.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows unauthenticated attackers to bypass application-level input validation to interact directly with the database. Consequences include the loss of sensitive data via unauthorized queries, database modification or deletion, and potential privilege escalation within the context of the database service. The scope includes any environment utilizing PyAthena versions earlier than 3.35.4.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eUpgrade the PyAthena library to version 3.35.4 or later immediately to patch the vulnerable DefaultParameterFormatter.format() implementation.\u003c/li\u003e\n\u003cli\u003eImplement strict input validation at the application layer to sanitize all parameters passed to PyAthena, rejecting inputs containing single quotes, semicolons, or SQL comment syntax.\u003c/li\u003e\n\u003cli\u003eEnforce the principle of least privilege for the database credentials used by the application, ensuring the service user lacks permissions to execute destructive commands (e.g., DROP, DELETE) or access unauthorized tables.\u003c/li\u003e\n\u003cli\u003eReview application code for direct concatenation of user-supplied variables into SQL queries, transitioning instead to parameterized queries wherever supported by the underlying connector logic.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-08-02T15:36:20Z","date_published":"2026-08-02T15:36:20Z","id":"https://feed.craftedsignal.io/briefs/2026-08-pyathena-sql-injection/","summary":"Unauthenticated attackers can achieve arbitrary SQL execution in PyAthena versions prior to 3.35.4 by exploiting improper quote-escaping within the DefaultParameterFormatter.format() function.","title":"SQL Injection in PyAthena DefaultParameterFormatter","url":"https://feed.craftedsignal.io/briefs/2026-08-pyathena-sql-injection/"}],"language":"en","title":"CraftedSignal Threat Feed - PyAthena (\u003c 3.35.4)","version":"https://jsonfeed.org/version/1.1"}