PT-2026-57680 · Apache · Apache Gravitino

·

CVE-2026-49876

·

Published

2026-07-13

·

Updated

2026-07-14

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Apache Gravitino versions 1.0.0 through 1.2.1
Description An authenticated Server-Side Request Forgery (SSRF) exists in the Gravitino JobManager. This allows an attacker to trigger server-side HTTP requests to internal networks and cloud metadata endpoints by providing unvalidated job template URIs. SSRF is a flaw where a server is tricked into making requests to an unintended location.
Recommendations Upgrade to version 1.3.0.

Exploit

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-49876
PYSEC-2026-3442

Affected Products

Apache Gravitino