CVE-2026-28438: 
Python vulnerability analysis and mitigation

Overview

CVE-2026-28438 is a SQL injection vulnerability in the Doris target connector of CocoIndex, an open-source data transformation framework for AI applications. The vulnerability affects CocoIndex versions prior to 0.3.34 (specifically identified in version 0.3.28) and was published on March 6, 2026. It arises when the Doris connector constructs ALTER TABLE SQL statements without validating the configured table name, allowing injection if the table name originates from an untrusted upstream source. The CVSS v3.1 base score is 9.8 (Critical) (GitHub Advisory, Red Hat CVE).

Technical details

The root cause is CWE-89 (Improper Neutralization of Special Elements used in an SQL Command), classified as a classic SQL injection flaw. The Doris target connector in CocoIndex directly interpolates user-supplied table names into ALTER TABLE SQL statements during target schema change operations without any identifier validation or sanitization. Exploitation requires that the table name be sourced from an untrusted upstream (e.g., end-user input passed into the CocoIndex pipeline configuration), and the attack is network-accessible with no authentication or user interaction required. The fix in version 0.3.34 introduces validation of table names at the entry point, erroring out immediately if the name is not a valid SQL identifier (GitHub Advisory, Patch Commit).

Impact

Successful exploitation could allow an attacker to execute arbitrary SQL commands against the underlying Doris database, resulting in unauthorized data access (confidentiality breach), unauthorized data modification or deletion (integrity breach), and potential denial of service or database unavailability (availability impact). The vulnerability is particularly dangerous in multi-tenant or user-facing deployments of CocoIndex where table names may be dynamically supplied by end users, as it could expose the entire database to compromise. Given the network-accessible, unauthenticated nature of the attack vector, the blast radius extends to all data managed by the connected Doris instance (GitHub Advisory).

Exploitability

There is no public proof-of-concept exploit code and no evidence of in-the-wild exploitation at this time. The EPSS score is approximately 0.03%, indicating a low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation is conditional on the application being configured to accept table names from untrusted sources, which limits the attack surface to specific deployment patterns (GitHub Advisory, Red Hat CVE).

Exploitation steps

  1. Identify target: Locate a CocoIndex deployment (prior to version 0.3.34) that uses the Doris target connector and accepts table names from user-controlled or untrusted upstream input.
  2. Craft malicious table name: Prepare a table name payload containing SQL injection syntax, such as legitimate_table; DROP TABLE sensitive_data; -- or a subquery to exfiltrate data.
  3. Inject via upstream input: Supply the malicious table name through whatever mechanism the application exposes (e.g., API parameter, configuration input, pipeline trigger) that feeds into the CocoIndex Doris target connector configuration.
  4. Trigger schema change: Cause CocoIndex to execute a target schema change operation (e.g., by initiating a pipeline run or schema update), which causes the Doris connector to construct and execute an ALTER TABLE statement incorporating the unsanitized table name.
  5. Achieve SQL execution: The injected SQL is executed against the Doris database with the privileges of the CocoIndex database user, enabling data exfiltration, modification, deletion, or further lateral movement within the database (GitHub Advisory).

Indicators of compromise

  • Logs: Database query logs showing ALTER TABLE statements with unexpected SQL syntax, semicolons, comment sequences (--, /**/), or subqueries embedded in table name fields; CocoIndex application logs showing errors related to unexpected SQL execution or schema change failures.
  • Database: Unexpected schema changes, dropped tables, or new database objects created in the Doris instance; unusual data access patterns or bulk data reads following schema change operations.
  • Application: CocoIndex pipeline runs triggered with anomalous or non-standard table name values; configuration entries referencing table names containing special characters or SQL keywords.

Mitigation and workarounds

Upgrade CocoIndex to version 0.3.34 or later, which validates table names at the entry point of the Doris target connector and rejects any name that is not a valid SQL identifier (GitHub Advisory, Patch Commit). As a workaround prior to patching, ensure all table names used to configure CocoIndex Doris targets originate from trusted, controlled sources (e.g., hardcoded string literals) rather than user-supplied input. If table names must come from external sources, implement strict allowlist validation (alphanumeric characters and underscores only) before passing them to the CocoIndex configuration. Additionally, restrict network access to the CocoIndex application and its Doris database connections to trusted hosts only.

Community reactions

The vulnerability was credited to researcher 4ur0n as the finder and was published as a GitHub Security Advisory (GHSA-59g6-v3vg-f7wc) by the CocoIndex maintainer georgeh0 on February 28, 2026. Red Hat tracked the issue in their CVE database. Community coverage was limited to automated CVE tracking feeds and security aggregators, with no significant broader media or researcher commentary observed (GitHub Advisory, Red Hat CVE).

Additional resources


Source: This report was generated using AI

Related Python vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

GHSA-v2f8-6655-7grjCRITICAL10
  • Python logoPython
  • vibe-trading-ai
NoYesOct 02, 2026
CVE-2026-105782HIGH7.5
  • Python logoPython
  • scrapy
NoYesOct 06, 2026
GHSA-v853-p72q-4cfwHIGH7.5
  • Python logoPython
  • quart
NoYesOct 05, 2026
CVE-2026-105751MEDIUM6.9
  • Python logoPython
  • docling
NoYesOct 05, 2026
CVE-2026-105750MEDIUM5.9
  • Python logoPython
  • docling
NoYesOct 05, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management