Hadoop
Vendor:
First CVE: Apr 12, 2012 · Active for 14 years
37
Total CVEs
More Total CVEs than 97% of tracked products
3.1
Avg CVEs / Year
Higher CVE frequency than 81% of tracked products
7.8
Avg CVSS
Higher Avg CVSS than 67% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Hadoop over time
Volume of CVEsAvg CVSS Base Score
First CVE
Apr 12, 2012
14 years ago
Most Recent CVE
Jan 26, 2026
179 days ago
CVE Severity & Scoring
Hadoop37 CVEs
22%
57%
19%
All CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local5 (13.5%)
Network28 (75.7%)
Unknown4 (10.8%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low30 (81.1%)
High3 (8.1%)
Unknown4 (10.8%)
User Interaction
None32 (86.5%)
Unknown4 (10.8%)
Required1 (2.7%)
Privileges Required
Low15 (40.5%)
High0 (0.0%)
None18 (48.6%)
Unknown4 (10.8%)
Top CVEs
Signals from CVEs in this product scope (37 CVEs).
37 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-17195CRITICAL Connect2id Nimbus JOSE+JWT before v7.9 can throw various uncaught exceptions while parsing a JWT, which could result in an application crash (potential information disclosure) or a | Oct 15, 2019 | 9.8 | 38 | NO | NO |
CVE-2022-26612CRITICAL In Apache Hadoop, The unTar function uses unTarUsingJava function on Windows and the built-in tar utility on Unix and other OSes. As a result, a TAR entry may create a symlink unde | Apr 7, 2022 | 9.8 | 33 | NO | NO |
CVE-2021-37404CRITICAL There is a potential heap buffer overflow in Apache Hadoop libhdfs native code. Opening a file path provided by user without validation may result in a denial of service or arbitra | Jun 13, 2022 | 9.8 | 32 | NO | NO |
CVE-2017-15718CRITICAL The YARN NodeManager in Apache Hadoop 2.7.3 and 2.7.4 can leak the password for credential store provider used by the NodeManager to YARN Applications. | Jan 24, 2018 | 9.8 | 32 | NO | NO |
CVE-2018-8009HIGH Apache Hadoop 3.1.0, 3.0.0-alpha to 3.0.2, 2.9.0 to 2.9.1, 2.8.0 to 2.8.4, 2.0.0-alpha to 2.7.6, 0.23.0 to 0.23.11 is exploitable via the zip slip vulnerability in places that acce | Nov 13, 2018 | 8.8 | 31 | NO | NO |
CVE-2016-3086CRITICAL The YARN NodeManager in Apache Hadoop 2.6.x before 2.6.5 and 2.7.x before 2.7.3 can leak the password for credential store provider used by the NodeManager to YARN Applications. | Sep 5, 2017 | 9.8 | 31 | NO | NO |
CVE-2021-33036HIGH In Apache Hadoop 2.2.0 to 2.10.1, 3.0.0-alpha1 to 3.1.4, 3.2.0 to 3.2.2, and 3.3.0 to 3.3.1, a user who can escalate to yarn user can possibly run arbitrary commands as root user. | Jun 15, 2022 | 8.8 | 30 | NO | NO |
CVE-2020-9492HIGH In Apache Hadoop 3.2.0 to 3.2.1, 3.0.0-alpha1 to 3.1.3, and 2.0.0-alpha to 2.10.0, WebHDFS client might send SPNEGO authorization header to remote URL without proper verification. | Jan 26, 2021 | 8.8 | 30 | NO | NO |
CVE-2021-25642HIGH ZKConfigurationStore which is optionally used by CapacityScheduler of Apache Hadoop YARN deserializes data obtained from ZooKeeper without validation. An attacker having access to | Aug 25, 2022 | 8.8 | 29 | NO | NO |
CVE-2018-11764HIGH Web endpoint authentication check is broken in Apache Hadoop 3.0.0-alpha4, 3.0.0-beta1, and 3.0.0. Authenticated users may impersonate any user even if no proxy user is configured. | Oct 21, 2020 | 8.8 | 29 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (37 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (37 CVEs).
Media Mentions
Signals from CVEs in this product scope (37 CVEs).
Top CNAs Publishing CVEs For Hadoop
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 3.3.2 | 1 | 9.8 | 4.2% | 0 | 0 |
| 3.3.1 | 1 | 9.8 | 4.2% | 0 | 0 |
| 3.2.1 | 1 | 9.8 | 11.0% | 0 | 0 |
| 3.1.0 | 1 | 8.8 | 7.6% | 0 | 0 |
| 3.0.0 | 10 | 8.0 | 4.2% | 0 | 0 |
| 2.9.1 | 1 | 8.8 | 4.0% | 0 | 0 |
| 2.9.0 | 2 | 8.2 | 3.6% | 0 | 0 |
| 2.8.3 | 1 | 7.5 | 3.3% | 0 | 0 |
| 2.8.2 | 1 | 7.5 | 3.3% | 0 | 0 |
| 2.8.1 | 1 | 7.5 | 3.3% | 0 | 0 |
| 2.8.0 | 2 | 7.5 | 2.5% | 0 | 0 |
| 2.7.4 | 1 | 9.8 | 3.6% | 0 | 0 |
| 2.7.3 | 2 | 8.8 | 2.0% | 0 | 0 |
| 2.7.2 | 3 | 8.8 | 2.4% | 0 | 0 |
| 2.7.1 | 4 | 8.0 | 1.9% | 0 | 0 |
| 2.7.0 | 5 | 8.1 | 1.7% | 0 | 0 |
| 2.6.5 | 1 | 7.8 | 0.4% | 0 | 0 |
| 2.6.4 | 4 | 8.2 | 1.9% | 0 | 0 |
| 2.6.3 | 4 | 8.2 | 1.9% | 0 | 0 |
| 2.6.2 | 4 | 8.2 | 1.9% | 0 | 0 |