🔐 CVE Alert

CVE-2026-23904

UNKNOWN 0.0

Apache Kyuubi: Unrestricted access via Kyuubi engine-ui proxy

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Kyuubi Engine UI proxy accepts a host and port from the request path and proxies HTTP requests to that destination. A remote requester with network access to the proxy can cause the Kyuubi server to send HTTP requests to arbitrary reachable hosts, resulting in SSRF or open-proxy behavior. This issue affects Apache Kyuubi: from 1.8.0 before 1.12.0. Users are recommended to upgrade to version 1.12.0, which disables the proxy by default. To restore proxied Engine UI, set kyuubi.frontend.rest.engine.ui.proxy.enabled=true and configure allowed target hosts with kyuubi.frontend.rest.engine.ui.proxy.hosts.

CWE CWE-923
Vendor apache software foundation
Product apache kyuubi
Published Jul 29, 2026
Last Updated Jul 29, 2026
Stay Ahead of the Next One

Get instant alerts for apache software foundation apache kyuubi

Be the first to know when new unknown vulnerabilities affecting apache software foundation apache kyuubi are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

Affected Versions

Apache Software Foundation / Apache Kyuubi
1.8.0 < 1.12.0

References

NVD ↗ CVE.org ↗ EPSS Data ↗
github.com: https://github.com/apache/kyuubi/pull/7483 lists.apache.org: https://lists.apache.org/thread/ps79fcfx49ox9kwgztc5t5bw0tyhck9m openwall.com: http://www.openwall.com/lists/oss-security/2026/07/29/3

Credits

🔍 Ícaro Torres