Every CVE whose affected-product data names Apache Gravitino, ordered by CVSS severity, with EPSS exploit prediction and CISA KEV status.
CVEs (3)
CVE-2026-41041 — CVSS 9.1 (critical): URL path injection via unencoded user-supplied identifiers vulnerability in Apache Gravitino. This issue affects Apache Gravitino: from…
CVE-2026-49876 — CVSS 6.5 (medium): Authenticated SSRF in Gravitino JobManager allows server-side HTTP requests to internal network and cloud metadata endpoints via…
CVE-2025-53648 — CVSS 5.4 (medium): SQL misconfiguration in the Gravitino UI, in versions 1.0.0 and below, can allow a malicious user to read or truncate files. Users are…