PT-2026-65742 · Apache+1 · Apache Kyuubi+1

·

CVE-2026-23904

·

Published

2026-07-29

·

Updated

2026-08-05

CVSS v3.1

7.3

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions Apache Kyuubi versions 1.8.0 through 1.11.x
Description The Engine UI proxy accepts a host and port from the request path and proxies HTTP requests to that destination. A remote requester with network access to the proxy can cause the server to send HTTP requests to arbitrary reachable hosts, leading to Server-Side Request Forgery (SSRF), where the server is tricked into making requests to internal or external resources, or open-proxy behavior.
Recommendations Upgrade to version 1.12.0. To restore proxied Engine UI after upgrading, set kyuubi.frontend.rest.engine.ui.proxy.enabled to true and configure allowed target hosts using kyuubi.frontend.rest.engine.ui.proxy.hosts.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-23904

Affected Products

Apache Kyuubi
Kyuubi