maven package report

Is io.trino:trino-iceberg safe?

1 known vulnerability, worst severity HIGH.

cvss
7.7

how bad it is if exploited, out of 10

epss
0.20%

chance of exploitation in the next 30 days

xyz score
3.3

CyberXYZ composite, out of 10

fig. 01 — GHSA-x27p-5f68-m644, the advisory selected below

// advisories

GHSA-x27p-5f68-m644

HIGHCVE-2026-34214

Iceberg connector REST catalog static credentials (access key) or vended credentials (temporary access key) are accessible to users that have write privilege on SQL level.

Affected
>= 439, < 480
Fixed in
480
Weakness
CWE-212
Published
2026-03-29
Source
github

GHSANVDMITREreferencereference


// ai model usage

Tracked for PyPI packages. HuggingFace models declare Python dependencies, so maven packages are not covered.


Checked 2026-09-22 at 00:56 UTC. The most recent advisory here was published 2026-03-29. Updated continuously from NVD, GHSA, OSV and CNA feeds.

Think a verdict here is wrong? Tell us — we respond within 2 business days.
Is io.trino:trino-iceberg safe? maven package security report | CyberXYZ