[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"repo-stars":3,"vuln-CVE-2026-77810":6},{"stargazers_count":4,"fetched_at":5},7,"2026-08-21T15:42:55.914Z",{"id":7,"descriptions":8,"cisa":9,"weaknesses":10,"exploits":54,"aliases":55,"duplicate_of":9,"upstream":56,"downstream":57,"duplicates":58,"related":59,"reserved_at":9,"published_at":60,"modified_at":61,"state":62,"summary":63,"references_raw":70,"kevs":86,"epss":9,"epss_history":87,"metrics":88,"affected":97},"CVE-2026-77810","In the Neptune connector, a user with access to Neptune through Athena Federated Query could gain access to properties in the Lambda supplying the compute for the connector. To remediate this issue, users should upgrade to aws-athena-query-federation v2026.30.1 or later.",null,[11],{"_key":12,"id":12,"name":13,"description":14,"type":15,"status":16,"abstraction":17,"likelihood_of_exploit":18,"capec":19},"CWE-95","Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection')","The product receives input from an upstream component, but it does not neutralize or incorrectly neutralizes code syntax before using the input in a dynamic evaluation call (e.g. \"eval\").","weakness","Incomplete","Variant","Medium",[20],{"id":21,"name":22,"techniques":23},"CAPEC-35","Leverage Executable Code in Non-Executable Files",[24,35,42],{"id":25,"name":26,"tactics":27,"countermeasures":34},"T1027.006","HTML Smuggling",[28,31],{"id":29,"name":30},"TA0030","Defense Evasion",{"id":32,"name":33},"TA0005","Stealth",[],{"id":36,"name":37,"tactics":38,"countermeasures":41},"T1027.009","Embedded Payloads",[39,40],{"id":29,"name":30},{"id":32,"name":33},[],{"id":43,"name":44,"tactics":45,"countermeasures":48},"T1564.009","Resource Forking",[46,47],{"id":29,"name":30},{"id":32,"name":33},[49],{"id":50,"name":51,"tactic":52},"D3-FFV","File Format Verification",{"name":53},"Isolate",[],[],[],[],[],[],"2026-08-21T19:34:06.041Z","2026-08-21T19:35:39.067Z","PUBLISHED",{"cisa_kev":64,"cisa_ransomware":64,"cisa_vendor":9,"epss_severity":9,"epss_score":9,"severity":65,"severity_score":66,"severity_version":67,"severity_source":68,"severity_vector":69,"severity_status":62},false,"critical",9.9,"v3.1","cve.org","CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",[71,76,81],{"url":72,"sources":73,"tags":74},"https://github.com/awslabs/aws-athena-query-federation/releases/tag/v2026.30.1",[68],[75],"Patch",{"url":77,"sources":78,"tags":79},"https://aws.amazon.com/security/security-bulletins/2026-087-aws/",[68],[80],"Vendor Advisory",{"url":82,"sources":83,"tags":84},"https://github.com/awslabs/aws-athena-query-federation/security/advisories/GHSA-v7c2-5wfg-qg44",[68],[85],"Third Party Advisory",[],[],[89],{"source":68,"cvss_v2_0":9,"cvss_v3_0":9,"cvss_v3_1":90,"cvss_v4_0":94},{"baseScore":66,"baseSeverity":91,"vectorString":69,"impactScore":92,"exploitabilityScore":93},"CRITICAL",10,7.9,{"baseScore":95,"baseSeverity":91,"vectorString":96,"impactScore":9,"exploitabilityScore":9},9.4,"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H",[98],{"ecosystem":9,"name":99,"vendor":100,"product":101,"cpe_part":102,"purl_type":9,"purl_namespace":9,"purl_name":9,"source":9,"versions":103},"Athena Federated Query Neptune Connector","aws","athena federated query neptune connector","a",[104],{"version":105,"is_range":106,"range_type":68,"version_start":107,"version_start_type":108,"version_end":109,"version_end_type":108,"fixed_in":9},">= 2024.15.1, \u003C= 2026.28.1",true,"2024.15.1","including","2026.28.1"]