yousukezan[verified]@yousukezanDisclosure
Apache Flink’s CVE‑2026‑35194 exposes a severe RCE through SQL injection; affected versions are listed and the vendor has released a patch with update guidance.
elhacker.NET@elhackernetDisclosure
Apache Flink’s CVE‑2026‑35194 is a critical vulnerability that allows remote code execution via unsanitized user input, also enabling SQL injection, though no exploitation or patch details are provided.
Gray Hats@the_yellow_fallPatch
A critical RCE vulnerability (CVE‑2026‑35194) in Apache Flink allows SQL injection on TaskManagers; users are urged to upgrade their clusters to mitigate the risk.
Open Source Security mailing list@oss_securityDisclosure
The advisory discloses CVE-2026-35194 as a critical remote code execution flaw in Apache Flink caused by unsanitized user input in code generation, but does not provide a PoC, exploit, or patch information.
ケイ | IT・セキュリティ系副業Webライター@Teeeda_workerGeneral
The post merely announces that CVE‑2026‑35194 affects specific Apache Flink versions and provides a link to an external page, offering no technical details, exploit information, or mitigation guidance.
ケイ | IT・セキュリティ系副業Webライター@Teeeda_workerDisclosure
The post announces the existence of CVE-2026-35194 affecting certain Apache Flink releases, linking to a source for details, but provides no specific technical, exploit, or mitigation information.
iototsecnews@iototsecnewsDisclosure
The article discloses a remote code execution flaw in Apache Flink caused by unsafe string interpolation during SQL-to-Java code generation, but it does not provide a PoC, patch, or evidence of active exploitation.
cybersecuritypath@cybrsecpathDisclosures
Apache Flink RCE vulnerability (CVE-2026-35194) has been disclosed, potentially enabling remote code execution on clusters, with no exploit or patch information provided.