Skip to content
AWSAWS-2026-013

Issues with Amazon Athena ODBC Driver

UnratedCVE-2026-5485 · Published Apr 3, 2026 · updated Sep 25, 2026

Bulletin ID:  2026-013-AWS Scope: AWS Content Type:  Important (requires attention) Publication Date: 04/3/2026 1:00 PM PST Description: The Amazon Athena ODBC driver implements standard ODBC application program interfaces (APIs). The ODBC driver provides access to Amazon Athena from any C/C++ application. The Amazon Athena ODBC driver provides 64-bit ODBC drivers for Windows, Linux and MAC operating systems. We identified the following: CVE-2026-5485 : OS command injection in browser-based authentication component (Linux only, fixed in 2.0.5.1) CVE-2026-35558 : Improper neutralization of special elements in authentication components CVE-2026-35559 : Out-of-bounds write in query processing components CVE-2026-35560 : Improper certificate validation in identity provider connection components CVE-2026-35561 : Insufficient authentication security controls in browser-based authentication components CVE-2026-35562 : Allocation of resources without limits in parsing components Impacted versions : CVE-2026-5485 was addressed in 2.0.5.1 (Linux only). The remaining five (CVE-2026-35558 through CVE-2026-35562) were addressed in version 2.1.0.0 and apply to all supported platforms R...

AWS advisory

Affected versions

The source does not list versions here. See the source advisory for affected products and fixes.
Details and references

Bulletin ID:  2026-013-AWS Scope: AWS Content Type:  Important (requires attention) Publication Date: 04/3/2026 1:00 PM PST Description: The Amazon Athena ODBC driver implements standard ODBC application program interfaces (APIs). The ODBC driver provides access to Amazon Athena from any C/C++ application. The Amazon Athena ODBC driver provides 64-bit ODBC drivers for Windows, Linux and MAC operating systems. We identified the following: CVE-2026-5485 : OS command injection in browser-based authentication component (Linux only, fixed in 2.0.5.1) CVE-2026-35558 : Improper neutralization of special elements in authentication components CVE-2026-35559 : Out-of-bounds write in query processing components CVE-2026-35560 : Improper certificate validation in identity provider connection components CVE-2026-35561 : Insufficient authentication security controls in browser-based authentication components CVE-2026-35562 : Allocation of resources without limits in parsing components Impacted versions : CVE-2026-5485 was addressed in 2.0.5.1 (Linux only). The remaining five (CVE-2026-35558 through CVE-2026-35562) were addressed in version 2.1.0.0 and apply to all supported platforms Resolution: This issue has been addressed in Amazon Athena ODBC driver version 2.1.0.0. We recommend upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes. Workarounds No workaround is available. Reference: Windows - https://downloads.athena.us-east-1.amazonaws.com/drivers/ODBC/v2.1.0.0/Windows/AmazonAthenaODBC-2.1.0.0.msi Linux - https://downloads.athena.us-east-1.amazonaws.com/drivers/ODBC/v2.1.0.0/Linux/AmazonAthenaODBC-2.1.0.0.rpm macOS 64-bit (ARM) - https://downloads.athena.us-east-1.amazonaws.com/drivers/ODBC/v2.1.0.0/Mac/arm/AmazonAthenaODBC-2.1.0.0_arm.pkg macOS 64-bit (Intel) - https://downloads.athena.us-east-1.amazonaws.com/drivers/ODBC/v2.1.0.0/Mac/Intel/AmazonAthenaODBC-2.1.0.0_x86.pkg   Please email aws-security@amazon.com with any security questions or concerns.   "},"metadata":{"tags":[]}},{"fields":{"patternBoolean2":"false","id":"ams#rt-rich-textc2#pattern-data"},"metadata":{"tags":[{"name":"pattern-data","description":"Default pattern data","id":"ams#rt-rich-textc2#pattern-data","namespaceId":"rt-rich-text"}]}}]},"metadata":{"auth":{},"testAttributes":{}},"context":{"page":{"pageUrl":"https://aws.amazon.com/security/security-bulletins/2026-013-aws/"},"contentType":"page","environment":{"stage":"prod","region":"us-west-2"},"sdkVersion":"2.0.27"},"refMap":{"manifest.js":"cda3e8d042","rt-rich-text.js":"5043b0a87f","rt-rich-text.rtl.css":"6a04028f86","rt-rich-text.css":"98f5a6aee4","rt-rich-text.css.js":"3d619cc2e1","rt-rich-text.rtl.css.js":"ccdb945d3e"},"settings":{"templateMappings":{"patternHeading":"patternHeading","patternSubheading":"patternSubheading","patternDark":"patternBoolean2","title":"itemHeading","bodyText":"itemLongLoc"}}} Issues with Amazon Athena ODBC Driver Bulletin ID:  2026-013-AWS Scope: AWS Content Type:  Important (requires attention) Publication Date: 04/3/2026 1:00 PM PST Description: The Amazon Athena ODBC driver implements standard ODBC application program interfaces (APIs). The ODBC driver provides access to Amazon Athena from any C/C++ application. The Amazon Athena ODBC driver provides 64-bit ODBC drivers for Windows, Linux and MAC operating systems. We identified the following: CVE-2026-5485 : OS command injection in browser-based authentication component (Linux only, fixed in 2.0.5.1) CVE-2026-35558 : Improper neutralization of special elements in authentication components CVE-2026-35559 : Out-of-bounds write in query processing components CVE-2026-35560 : Improper certificate validation in identity provider connection components CVE-2026-35561 : Insufficient authentication security controls in browser-based authentication components CVE-2026-35562 : Allocation of resources without limits in parsing components Impacte

Severity from
no source yet
Also known as
CVE-2026-35558, CVE-2026-35559, CVE-2026-35560, CVE-2026-35561, CVE-2026-35562

More AWS advisories

All AWS
Advisory
Out-of-bounds Write in Firecracker virtio-pci Transport
UnratedApr 7
Issues with AWS Research and Engineering Studio (RES)
UnratedApr 6
Kiro IDE Webview Cross-Site Scripting via Workspace Color Theme
UnratedApr 2
AWS C Event Stream Streaming Decoder Stack Buffer Overflow
UnratedMar 31
Defense in depth enhancement for CloudFront signing utility in AWS Tools for PowerShell
High7.7Mar 26
Defense in depth enhancement for CloudFront signing utility in AWS SDK for .NET
High7.7Mar 26

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.