Hadoop

Vendor:

First CVE: Apr 12, 2012 · Active for 14 years

37
Total CVEs
More Total CVEs than 97% of tracked products
3.1
Avg CVEs / Year
Higher CVE frequency than 81% of tracked products
7.8
Avg CVSS
Higher Avg CVSS than 67% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Hadoop over time

Volume of CVEsAvg CVSS Base Score
First CVE
Apr 12, 2012
14 years ago
Most Recent CVE
Jan 26, 2026
179 days ago

CVE Severity & Scoring

Hadoop37 CVEs
All CVEs352,231 CVEs
LowMediumHighCritical
Attack Vector
Local5 (13.5%)
Network28 (75.7%)
Unknown4 (10.8%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low30 (81.1%)
High3 (8.1%)
Unknown4 (10.8%)
User Interaction
None32 (86.5%)
Unknown4 (10.8%)
Required1 (2.7%)
Privileges Required
Low15 (40.5%)
High0 (0.0%)
None18 (48.6%)
Unknown4 (10.8%)

Top CVEs

Signals from CVEs in this product scope (37 CVEs).

37 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Connect2id Nimbus JOSE+JWT before v7.9 can throw various uncaught exceptions while parsing a JWT, which could result in an application crash (potential information disclosure) or a
Oct 15, 20199.838NONO
In Apache Hadoop, The unTar function uses unTarUsingJava function on Windows and the built-in tar utility on Unix and other OSes. As a result, a TAR entry may create a symlink unde
Apr 7, 20229.833NONO
There is a potential heap buffer overflow in Apache Hadoop libhdfs native code. Opening a file path provided by user without validation may result in a denial of service or arbitra
Jun 13, 20229.832NONO
The YARN NodeManager in Apache Hadoop 2.7.3 and 2.7.4 can leak the password for credential store provider used by the NodeManager to YARN Applications.
Jan 24, 20189.832NONO
Apache Hadoop 3.1.0, 3.0.0-alpha to 3.0.2, 2.9.0 to 2.9.1, 2.8.0 to 2.8.4, 2.0.0-alpha to 2.7.6, 0.23.0 to 0.23.11 is exploitable via the zip slip vulnerability in places that acce
Nov 13, 20188.831NONO
The YARN NodeManager in Apache Hadoop 2.6.x before 2.6.5 and 2.7.x before 2.7.3 can leak the password for credential store provider used by the NodeManager to YARN Applications.
Sep 5, 20179.831NONO
In Apache Hadoop 2.2.0 to 2.10.1, 3.0.0-alpha1 to 3.1.4, 3.2.0 to 3.2.2, and 3.3.0 to 3.3.1, a user who can escalate to yarn user can possibly run arbitrary commands as root user.
Jun 15, 20228.830NONO
In Apache Hadoop 3.2.0 to 3.2.1, 3.0.0-alpha1 to 3.1.3, and 2.0.0-alpha to 2.10.0, WebHDFS client might send SPNEGO authorization header to remote URL without proper verification.
Jan 26, 20218.830NONO
ZKConfigurationStore which is optionally used by CapacityScheduler of Apache Hadoop YARN deserializes data obtained from ZooKeeper without validation. An attacker having access to
Aug 25, 20228.829NONO
Web endpoint authentication check is broken in Apache Hadoop 3.0.0-alpha4, 3.0.0-beta1, and 3.0.0. Authenticated users may impersonate any user even if no proxy user is configured.
Oct 21, 20208.829NONO

Exploit Exposure

Signals from CVEs in this product scope (37 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (37 CVEs).

Media Mentions

Signals from CVEs in this product scope (37 CVEs).

Top CNAs Publishing CVEs For Hadoop

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
3.3.219.84.2%00
3.3.119.84.2%00
3.2.119.811.0%00
3.1.018.87.6%00
3.0.0108.04.2%00
2.9.118.84.0%00
2.9.028.23.6%00
2.8.317.53.3%00
2.8.217.53.3%00
2.8.117.53.3%00
2.8.027.52.5%00
2.7.419.83.6%00
2.7.328.82.0%00
2.7.238.82.4%00
2.7.148.01.9%00
2.7.058.11.7%00
2.6.517.80.4%00
2.6.448.21.9%00
2.6.348.21.9%00
2.6.248.21.9%00