title: Apache Flink security advisories description: Security information for Apache Flink layout: single


Do you want disclose a potential security issue for Apache Flink? You can read more about the projects' security policy on their security page, and email your report to the Apache Security Team.


This section is experimental: it provides advisories since 2023 and may lag behind the official CVE publications. It may also lack details found on the project security page. If you have any feedback on how you would like this data to be provided, you are welcome to reach out on our public mailinglist or privately on security@apache.org {.bg-warning}

Apache Flink directory traversal attack: remote file writing through the REST API ## { #CVE-2020-17518 }

CVE-2020-17518 [CVE json]


  • Apache Flink at Apache Flink 1.5.1 to 1.11.2


Apache Flink 1.5.1 introduced a REST handler that allows you to write an uploaded file to an arbitrary location on the local file system, through a maliciously modified HTTP HEADER. The files can be written to any location accessible by Flink 1.5.1. All users should upgrade to Flink 1.11.3 or 1.12.0 if their Flink instance(s) are exposed. The issue was fixed in commit a5264a6f41524afe8ceadf1d8ddc8c80f323ebc4 from apache/flink:master.



  • 0rich1 of Ant Security FG Lab

Apache Flink directory traversal attack: reading remote files through the REST API ## { #CVE-2020-17519 }

CVE-2020-17519 [CVE json]


  • Apache Flink at Apache Flink 1.11.0 to 1.11.2


A change introduced in Apache Flink 1.11.0 (and released in 1.11.1 and 1.11.2 as well) allows attackers to read any file on the local filesystem of the JobManager through the REST interface of the JobManager process. Access is restricted to files accessible by the JobManager process. All users should upgrade to Flink 1.11.3 or 1.12.0 if their Flink instance(s) are exposed. The issue was fixed in commit b561010b0ee741543c3953306037f00d7a9f0801 from apache/flink:master.



  • 0rich1 of Ant Security FG Lab

Apache Flink Stateful Functions allowed HTTP header injection due to Improper Neutralization of CRLF Sequences ## { #CVE-2023-41834 }

CVE-2023-41834 [CVE json]


  • Apache Flink Stateful Functions from 3.1.0 through 3.2.0


Improper Neutralization of CRLF Sequences in HTTP Headers in Apache Flink Stateful Functions 3.1.0, 3.1.1 and 3.2.0 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via crafted HTTP requests. Attackers could potentially inject malicious content into the HTTP response that is sent to the user's browser.

Users should upgrade to Apache Flink Stateful Functions version 3.3.0.



  • Andrea Cosentino (finder)