CVE-2026-62391
- EPSS 0.52%
- Veröffentlicht 31.07.2026 09:58:15
- Zuletzt bearbeitet 10.08.2026 14:22:12
The security fix for CVE-2025-66518 is incomplete. Any client who can access to Apache Kyuubi Server via Kyuubi frontend protocols can bypass server-side config kyuubi.session.local.dir.allowlist via unprefixed Spark config aliases. This issue affec...
CVE-2026-52680
- EPSS 0.75%
- Veröffentlicht 30.07.2026 16:17:14
- Zuletzt bearbeitet 05.08.2026 17:22:23
Apache Kyuubi REST batch multipart upload handling uses the client-supplied multipart filename when creating a temporary uploaded resource. A remote attacker who can access the REST batch upload endpoint can provide path traversal sequences in the fi...
CVE-2026-23904
- EPSS 0.65%
- Veröffentlicht 29.07.2026 09:07:18
- Zuletzt bearbeitet 05.08.2026 18:36:12
Kyuubi Engine UI proxy accepts a host and port from the request path and proxies HTTP requests to that destination. A remote requester with network access to the proxy can cause the Kyuubi server to send HTTP requests to arbitrary reachable hosts, re...
CVE-2025-66518
- EPSS 0.91%
- Veröffentlicht 05.01.2026 08:46:27
- Zuletzt bearbeitet 07.10.2026 11:10:00
Any client who can access to Apache Kyuubi Server via Kyuubi frontend protocols can bypass server-side config kyuubi.session.local.dir.allow.list and use local files which are not listed in the config. This issue affects Apache Kyuubi: from 1.6.0 th...