
5 CVEs fixed in Apache Superset CVE-2026-23969: Exposure of Sensitive Information via Incomplete ClickHouse Function Filtering https://www.openwall.com/lists/oss-security/2026/02/24/4 CVE-2026-23980: Improper Neutralization of Special Elements used in a SQL Command https://www.openwall.com/lists/oss-security/2026/02/24/5 + next tweet
Post summary
Apache Superset has released patches for five CVEs, including CVE-2026-23969 and CVE-2026-23980, addressing sensitive information exposure and SQL injection issues.


