Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-23904— Apache Kyuubi: Unrestricted access via Kyuubi engine-ui proxy

Quick assessment

Affected
Apache Software Foundation Apache Kyuubi
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Apache kyuubi是美国Apache基金会开源的一个分布式SQL查询引擎。 Apache Kyuubi 1.8.0版本至1.12.0版本之前版本存在授权问题漏洞,该漏洞源于Kyuubi Engine UI代理接受请求路径中的主机和端口并代理HTTP请求到该目标,导致服务端请求伪造或开放代理行为。

AI Predicted 9.1 Difficulty: Trivial EPSS 0.52% · P43

Possible ATT&CK Techniques 2 AI

T1105 · Ingress Tool Transfer T1105.003

Affected Version Matrix 1

VendorProduct Version RangeStatus
Apache Software Foundation Apache Kyuubi 1.8.0< 1.12.0 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-23904

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Apache Kyuubi: Unrestricted access via Kyuubi engine-ui proxy
Source: CVE Program / CVE List V5
Vulnerability Description
Kyuubi Engine UI proxy accepts a host and port from the request path and proxies HTTP requests to that destination. A remote requester with network access to the proxy can cause the Kyuubi server to send HTTP requests to arbitrary reachable hosts, resulting in SSRF or open-proxy behavior. This issue affects Apache Kyuubi: from 1.8.0 before 1.12.0. Users are recommended to upgrade to version 1.12.0, which disables the proxy by default. To restore proxied Engine UI, set kyuubi.frontend.rest.engine.ui.proxy.enabled=true and configure allowed target hosts with kyuubi.frontend.rest.engine.ui.proxy.hosts.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
通信信道对预期端点的不适当限制
Source: CVE Program / CVE List V5
Vulnerability Title
Apache Kyuubi 授权问题漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Apache kyuubi是美国Apache基金会开源的一个分布式SQL查询引擎。 Apache Kyuubi 1.8.0版本至1.12.0版本之前版本存在授权问题漏洞,该漏洞源于Kyuubi Engine UI代理接受请求路径中的主机和端口并代理HTTP请求到该目标,导致服务端请求伪造或开放代理行为。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
Apache Software Foundation Apache Kyuubi 1.8.0 ~ 1.12.0 -

II. Public POCs for CVE-2026-23904

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-23904

登录查看更多情报信息。

Patches & Fixes for CVE-2026-23904 (1)

Mailing List Discussions for CVE-2026-23904 (1)

Same Patch Batch · Apache Software Foundation · 2026-07-29 · 41 CVEs total

CVE-2026-33267 10.0 CRITICAL Apache Traffic Server: Untrusted @ headers can spoof ATS internal metadata
CVE-2026-57834 10.0 CRITICAL Apache Traffic Server: Malformed chunked message body allows request smuggling
CVE-2026-58150 10.0 CRITICAL Apache Traffic Server: HTTP/2 requests with Transfer-Encoding are not rejected, allowing r
CVE-2026-58162 10.0 CRITICAL Apache Traffic Server: Certifier plugin trusts client SNI when generating certificates
CVE-2026-58155 9.3 CRITICAL Apache Traffic Server: Header-name length truncation enables header aliasing and request s
CVE-2026-41920 9.3 CRITICAL Apache Traffic Server: SNI to Host header matching policy is not properly enforced
CVE-2026-58154 8.9 HIGH Apache Traffic Server: Memory-safety errors in MIME and header parsing
CVE-2026-58157 8.7 HIGH Apache Traffic Server: Improper server-session reuse can expose data across client connect
CVE-2026-58182 8.6 HIGH Apache Traffic Server: ts_lua plugin has initialization and resource-handling errors
CVE-2026-58153 8.3 HIGH Apache Traffic Server: HTTP/2 to HTTP/1 conversion forwards origin trailers to clients uns
CVE-2026-58159 8.2 HIGH Apache Traffic Server: Listener and ACL handling allow access-control bypass
CVE-2026-58184 8.2 HIGH Apache Traffic Server: header_rewrite plugin cookie handling can corrupt memory
CVE-2026-58188 8.2 HIGH Apache Traffic Server: Memory-safety and limit-bypass errors across experimental plugins
CVE-2026-22068 8.2 HIGH Apache Traffic Server: Regex mappings match with malicious domain names
CVE-2026-58177 8.1 HIGH Apache Traffic Server: Memory-safety and path-traversal errors in the Cripts framework
CVE-2026-58179 8.1 HIGH Apache Traffic Server: regex_remap plugin overflows the stack from attacker input
CVE-2026-58161 7.5 HIGH Apache Traffic Server: Memory-safety errors in TLS and SNI handling can crash the server
CVE-2026-58175 7.5 HIGH Apache Traffic Server: HostDB SRV handling leaks memory
CVE-2026-58178 7.5 HIGH Apache Traffic Server: ESI plugin allows uncontrolled recursion and server-side request fo
CVE-2026-58180 7.5 HIGH Apache Traffic Server: txn_box plugin overflows the stack from attacker input

Showing top 20 of 41 CVEs. View all on vendor page &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2026-23904

No comments yet


Leave a comment