Synced 17 Jun 2026 06:32 UTC Account
← Apache Hive

Apache Hive vulnerabilities: known CVEs & security history

Apache · Data / Big Data · 20 tracked CVEs · 0 actively exploited · updated June 2026 · what is a CVE? →

This is the full list of known vulnerabilities (CVEs) across all Apache Hive release lines — 20 in total. A CVE here doesn't mean your version is affected — check Apache Hive's current status and the safe version to run.

20
known CVEs
0
actively exploited (KEV)
2
critical severity
0
ransomware-linked

Known Apache Hive CVEs

Actively-exploited and most-severe first. Open any CVE for full details.

CVESeverityCVSSEPSSYear
CVE-2018-21234 critical 9.8 8% 2020
CVE-2018-1282 critical 9.1 6% 2018
CVE-2022-41137 high 8.3 2% 2024
CVE-2015-7521 high 8.3 6% 2016
CVE-2018-11777 high 8.1 2% 2018
CVE-2021-34538 high 7.5 1% 2022
CVE-2020-13949 high 7.5 7% 2021
CVE-2016-3083 high 7.5 1% 2017
CVE-2015-1772 high 7.3 7% 2015
CVE-2023-35701 medium 6.6 1% 2024
CVE-2024-23953 medium 6.5 1% 2025
CVE-2024-23945 medium 5.9 1% 2024
CVE-2020-1926 medium 5.9 2% 2021
CVE-2024-29869 medium 5.5 0% 2025
CVE-2025-62728 medium 5.4 0% 2025
CVE-2018-1314 medium 4.3 2% 2018
CVE-2017-12625 medium 4.3 1% 2017
CVE-2018-1315 low 3.7 2% 2018
CVE-2018-1284 low 3.7 2% 2018
CVE-2014-0228 low 3.5 3% 2014

Is my Apache Hive version affected?

The list above spans every release. To know whether your version is affected — and the minimum safe version to upgrade to — check it directly.

Check your Apache Hive version → · Monitor Apache Hive for new CVEs →

Apache Hive vulnerabilities — frequently asked

How many known vulnerabilities does Apache Hive have?

IsItPatched tracks 20 CVEs for Apache Hive. 2 are critical-severity and 7 high-severity. These span every release line — what matters is whether the version you run is affected.

Does Apache Hive have any actively-exploited vulnerabilities?

None of Apache Hive's tracked CVEs are currently in CISA's KEV catalog — but new ones can be added at any time, so keep your version current.

What is the most severe Apache Hive vulnerability?

Among tracked issues, CVE-2018-21234 (CRITICAL, CVSS 9.8) ranks highest — a Insecure deserialization weakness.

Is Apache Hive safe to use?

It depends on the version. The latest supported Apache Hive release clears the known issues; older versions may still be affected. Check the exact version you run for a verdict.

CVE data aggregated from NVD, CISA KEV and EPSS (FIRST.org). Related: Apache Hive security status · Apache Hive end-of-life · actively-exploited CVEs. Always verify against Apache's advisories — see our disclaimer.