Back

CRITICAL

PyAthena SQL Injection via DefaultParameterFormatter DELETE/CTAS

Published Aug 2, 2026

Description

PyAthena prior to 3.35.4 contains a sql injection vulnerability that allows unauthenticated attackers to inject arbitrary SQL by exploiting improper quote-escaping in DefaultParameterFormatter.format(), which routes DELETE and CTAS statements to the _escape_hive function that backslash-escapes single quotes rather than doubling them. Because Athena and Trino do not treat backslashes as escape characters inside string literals, attacker-supplied input such as a single quote followed by SQL syntax causes the parser to terminate the string literal prematurely, enabling data exfiltration via UNION SELECT, execution of destructive statements, and attacker-controlled CTAS destination and content.

Affected products

Remediation

No remediation recorded yet.

Weaknesses (1)

References (6)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner VulnCheck
Published Aug 2, 2026
Updated Aug 6, 2026
Reserved Jul 21, 2026
CISA Vulnrichment
Updated Aug 3, 2026
NVD
Status Received
Modified Aug 6, 2026
Red Hat
Severity n/a
Public date n/a