CVE-2026-23904CWE-923

CVE-2026-23904

High · published July 29, 2026

CVSS v3.1
7.3
EPSS
1%
Percentile
42.6
In the wild
Unconfirmed
What it is

Kyuubi Engine UI proxy accepts a host and port from the request path and proxies HTTP requests to that destination. A remote requester with network access to the proxy can cause the Kyuubi server to send HTTP requests to arbitrary reachable hosts, resulting in SSRF or open-proxy behavior.

This issue affects Apache Kyuubi: from 1.8.0 before 1.12.0.

Users are recommended to upgrade to version 1.12.0, which disables the proxy by default. To restore proxied Engine UI, set kyuubi.frontend.rest.engine.ui.proxy.enabled=true and configure allowed target hosts with kyuubi.frontend.rest.engine.ui.proxy.hosts.

The record
Technical detail
CVSS v3.1
7.3 · HIGH
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
CVSS v4.0
Not supplied
EPSS
0.00524 · 42.6th percentile
Weakness
CWE-923 · Improper Restriction of Communication Channel to Intended Endpoints
Published
2026-07-29T14:16Z
Affected products (1)
ProductVersionsFixed in
apache/kyuubi≥ 1.8.0, < 1.12.01.12.0
References (3)
EPSS history
Timeline
  • 29 JUL 09:07Z
    Apache Kyuubi: Unrestricted access via Kyuubi engine-ui proxy
    cvelistv5