{"id":"CVE-2026-8178","summary":"Remote Code Execution via Unsafe Class Loading in Amazon Redshift JDBC Driver","details":"An issue exists in Amazon Redshift JDBC Driver versions prior to 2.2.2. Under certain conditions, the driver could load and execute arbitrary classes when processing JDBC connection URL parameters. An actor who can influence the connection URL could potentially execute code in the application context, provided a suitable class is available on the application's classpath.\n\n\n\nTo mitigate this issue, users should upgrade to version 2.2.2 or later.","aliases":["GHSA-wmmv-vvg5-993q"],"modified":"2026-08-12T16:09:23.215601Z","published":"2026-05-08T18:36:46.950Z","database_specific":{"cna_assigner":"AMZN","cwe_ids":["CWE-470"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/8xxx/CVE-2026-8178.json"},"references":[{"type":"ADVISORY","url":"https://aws.amazon.com/security/security-bulletins/2026-028-aws/"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/8xxx/CVE-2026-8178.json"},{"type":"ADVISORY","url":"https://github.com/aws/amazon-redshift-jdbc-driver/security/advisories/GHSA-wmmv-vvg5-993q"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-8178"},{"type":"FIX","url":"https://github.com/aws/amazon-redshift-jdbc-driver/releases/tag/v2.2.2"},{"type":"PACKAGE","url":"https://github.com/aws/amazon-redshift-jdbc-driver"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/aws/amazon-redshift-jdbc-driver","events":[{"introduced":"0"},{"fixed":"f8b5e0f053a981927db49acec24b920cb856909c"}],"database_specific":{"source":"REFERENCES"}}],"versions":["v2.2.1","v2.2.0","v2.1.0.34","v2.1.0.33","v2.1.0.32","v2.1.0.31","v2.1.0.30","v2.1.0.29","v2.1.0.28","v2.1.0.26","v2.1.0.25","v2.1.0.24","v2.1.0.23","v2.1.0.22","v2.1.0.21","v2.1.0.20","v2.1.0.19","v2.1.0.18","v2.1.0.17","v2.1.0.16","v2.1.0.14","v2.1.0.13","v2.1.0.12","v2.1.0.11","2.1.0.11","v2.1.0.10","v2.1.0.9","v2.1.0.8","v2.1.0.7","v2.1.0.6","v2.1.0.5","v2.1.0.4","v2.1.0.3","v2.1.0.2","v2.1.0.1","v2.0.0.7","v2.0.0.6","v2.0.0.5","v2.0.0.4","v2.0.0.3","v2.0.0.2","v2.0.0.1","v2.0.0.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-8178.json","vanir_signatures_modified":"2026-08-12T16:09:23Z","vanir_signatures":[{"deprecated":false,"digest":{"line_hashes":["183276723764642442021227140030932784281","9980312845226736702786475975787273512","4176453312962318763630750899119976397","226576026871728754956374146957934770156","273514546383196571683608208248985371244"],"threshold":0.9},"id":"CVE-2026-8178-4979b1a9","signature_type":"Line","signature_version":"v1","source":"https://github.com/aws/amazon-redshift-jdbc-driver/commit/f8b5e0f053a981927db49acec24b920cb856909c","target":{"file":"src/main/java/com/amazon/redshift/RedshiftConnection.java"}},{"signature_version":"v1","source":"https://github.com/aws/amazon-redshift-jdbc-driver/commit/f8b5e0f053a981927db49acec24b920cb856909c","target":{"file":"src/main/java/com/amazon/redshift/jdbc/RedshiftConnectionImpl.java","function":"initObjectTypes"},"deprecated":false,"digest":{"function_hash":"20707112758364468040286501724160506610","length":939},"id":"CVE-2026-8178-739fe9c1","signature_type":"Function"},{"signature_version":"v1","source":"https://github.com/aws/amazon-redshift-jdbc-driver/commit/f8b5e0f053a981927db49acec24b920cb856909c","target":{"file":"src/main/java/com/amazon/redshift/jdbc/RedshiftConnectionImpl.java"},"deprecated":false,"digest":{"line_hashes":["52297638782907272979842749224619786390","160842460070240797211085196988420667002","9671264503837736572467963858286390699","260595862865047996994698455150338319852","282692241412697938604064891112196524457","28620959763911048160910946459708332584","160498221485947594109322409499126934363","325775753760943537541569776384817819771","129609646341157626827423945432751566545","91482742935047240390675657741913663379","235800656643896860974692691293601870819","78293847051598451915352461859310639904","267436712134870115377913356756503165101","306709787135194044968745497579243793965","1510027037419087856044684384726847722","213499349901938574263571821072303562237","70327141548093956636747432840608508705","66610313417162716917280507647330864604","29560952656319937798333834318373512946","147054910802966217585420791302883002976","212845755112452731899559235981184601810","117178324811345819613454800425411037488","221597630475594385213942203222806086374","190173751563160178162598028236363859089","179180044336854412868254409018693838984","37479557905076896909582040427104569854","160116554069429921170229220967817098592","152485229798325412973069973077152851103","86641019051466830419135969501268581415","307424545829671304077245756947992946363","295747577431459138783214723720080232905","328550155374325234943634329962723945114"],"threshold":0.9},"id":"CVE-2026-8178-9e823680","signature_type":"Line"},{"deprecated":false,"digest":{"function_hash":"62081695060000825474947310952719264919","length":219},"id":"CVE-2026-8178-dfe95efc","signature_type":"Function","signature_version":"v1","source":"https://github.com/aws/amazon-redshift-jdbc-driver/commit/f8b5e0f053a981927db49acec24b920cb856909c","target":{"file":"src/main/java/com/amazon/redshift/jdbc/RedshiftConnectionImpl.java","function":"addDataType"}}]}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"}]}