View Ridge Security
Back to Cyber HoseVulnerabilities & CVEs

Critical SQL Injection in PyAthena 3.35.4 with CVSS 9.8

šŸ”“ CVEs & KEV

  • CVE-2026-65321 — PyAthena 3.35.4 — CVSS 9.8 — SQL Injection via DefaultParameterFormatter DELETE/CTASPyAthena CVE-2026-65321 allows SQL injection through the DefaultParameterFormatter in PyAthena version 3.35.4, affecting DELETE and CTAS operations.

  • CVE-2026-9856 — huggingface/transformers — CVSS 7.1 — Path Traversal A path traversal vulnerability in huggingface/transformers could allow attackers to access unauthorized files. šŸ“Ž Coverage: cve.threatint.com

  • CVE-2026-10848 — Zephyr OCPP 1.6 — CVSS 7.0 — Out-of-bounds read in RPC message parser The Zephyr OCPP 1.6 RPC message parser (parse_rpc_msg) contains an out-of-bounds read vulnerability. šŸ“Ž Coverage: cve.threatint.com

Need help assessing your exposure?

Start with the free Posture Self-Check to see where you stand against the current threat landscape.

Free Posture Self-Check