Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-54745— Kubeflow Pipelines: Unauthenticated SSRF and HTTP smuggling in Kubeflow Pipelines frontend /_proxy/ route, bypasses ENABLE_AUTHZ=true

Quick assessment

Affected
kubeflow pipelines
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Kubeflow Pipelines 允许用户构建和部署可移植、可扩展的机器学习工作流。 在 2.17.0 之前的版本中,Kubeflow Pipelines 的前端通过 中的 路由暴露了一个未认证的服务器端请求伪造(SSRF)漏洞。 函数接受由攻击者控制的任意 HTTP 或 HTTPS 目标地址,并将其源站传递给 ,但并未实施主机名白名单,也未对回环地址、链路本地地址、RFC1918 私有地址或集群内部地址进行过滤。 当 时,该路由位于授权中间件之外,并且可通过 、 、 、 和 等路径访问,包括通过精心构造的 头

CVSS 10.0 · Critical

Possible ATT&CK Techniques 1 AI

T1021 · Remote Services

Affected Version Matrix 1

VendorProduct Version RangeStatus
kubeflow pipelines < 2.17.0 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-54745

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Kubeflow Pipelines: Unauthenticated SSRF and HTTP smuggling in Kubeflow Pipelines frontend /_proxy/ route, bypasses ENABLE_AUTHZ=true
Source: CVE Program / CVE List V5
Vulnerability Description
Kubeflow Pipelines enables users to build and deploy portable, scalable machine learning workflows. Prior to 2.17.0, the Kubeflow Pipelines frontend exposes an unauthenticated server-side request forgery vulnerability through the /_proxy/ route in frontend/server/proxy-middleware.ts. The _routePathWithReferer() function accepts an arbitrary attacker-controlled HTTP or HTTPS target and passes its origin to createProxyMiddleware without a host allowlist or filtering for loopback, link-local, RFC1918, or cluster-local addresses. The route remains outside the authorization middleware when ENABLE_AUTHZ=true and is reachable through /apis/v1beta1/_proxy/, /apis/v2beta1/_proxy/, /pipeline/apis/v1beta1/_proxy/, and /pipeline/apis/v2beta1/_proxy/, including through a crafted Referer header. Requests can forward attacker-controlled methods, headers such as Authorization, Cookie, and X-Forwarded-For, and POST bodies to reachable internal services, while returning the upstream response to the unauthenticated client. This can expose cloud metadata credentials, Kubernetes or service APIs, and other cluster-internal endpoints to unauthorized read or modification. This issue is fixed in version 2.17.0.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
访问控制不恰当
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
kubeflow pipelines < 2.17.0 -

II. Public POCs for CVE-2026-54745

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-54745

登录查看更多情报信息。

Patches & Fixes for CVE-2026-54745 (1)

Vendor Advisories for CVE-2026-54745 (1)

Vendor Pages for CVE-2026-54745 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-54745

No comments yet


Leave a comment