Apache kyuubi是美国Apache基金会开源的一个分布式SQL查询引擎。 Apache Kyuubi 1.6.0版本至1.12.0之前版本存在路径遍历漏洞,该漏洞源于对CVE-2025-66518的修复不完整,任何可通过Kyuubi前端协议访问服务器的客户端能够利用未加前缀的Spark配置别名绕过服务端配置kyuubi.session.local.dir.allowlist,可能导致路径遍历。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Apache Software Foundation | Apache Kyuubi | 1.6.0< 1.12.0 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Apache Software Foundation | Apache Kyuubi | 1.6.0 ~ 1.12.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-64607 | Apache HttpComponents Client: Connection Leak on Content-Encoding Decode Error Leads to Po | |
| CVE-2026-44615 | Path traversal in NotebookRepo note and folder path composition |
No comments yet