CVE-2026-65321
PyAthena SQL Injection via Improper Quote Escaping
Halo Surface Signal: 2 out of 5 — less likely to be public-facing.
A SQL injection vulnerability exists in PyAthena due to improper quote escaping, enabling unauthenticated attackers to inject arbitrary SQL. This could lead to unauthorized data exfiltration, modification, or the creation of malicious tables. The impact depends on how PyAthena is integrated into affected systems.