Advisory Database
  • Advisories
  • Dependency Scanning
  1. maven
  2. ›
  3. io.trino/trino-iceberg
  4. ›
  5. CVE-2026-34214

CVE-2026-34214: Trino: Iceberg REST catalog static and vended credentials are accessible via query JSON

March 29, 2026

Iceberg connector REST catalog static credentials (access key) or vended credentials (temporary access key) are accessible to users that have write privilege on SQL level.

References

  • github.com/advisories/GHSA-x27p-5f68-m644
  • github.com/trinodb/trino
  • github.com/trinodb/trino/releases/tag/480
  • github.com/trinodb/trino/security/advisories/GHSA-x27p-5f68-m644
  • nvd.nist.gov/vuln/detail/CVE-2026-34214

Code Behaviors & Features

Detect and mitigate CVE-2026-34214 with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions starting from 439 before 480

Fixed versions

  • 480

Solution

Upgrade to version 480 or above.

Impact 7.7 HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N

Learn more about CVSS

Weakness

  • CWE-212: Improper Removal of Sensitive Information Before Storage or Transfer
  • CWE-312: Cleartext Storage of Sensitive Information

Source file

maven/io.trino/trino-iceberg/CVE-2026-34214.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Mon, 30 Mar 2026 12:18:52 +0000.