CVE-2026-23904
CVE-2026-23904 is a high-severity vulnerability in Apache Kyuubi with a CVSS 3.x base score of 7.3. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-923.
Key facts
- Severity: High (CVSS 3.x base score 7.3)
- EPSS exploit prediction: 1% (49th percentile)
- Actively exploited: Not listed in CISA KEV
- Weakness: CWE-923
- Affected product: Apache Kyuubi
- Published:
- Last modified:
Description
Kyuubi Engine UI proxy accepts a host and port from the request path and proxies HTTP requests to that destination. A remote requester with network access to the proxy can cause the Kyuubi server to send HTTP requests to arbitrary reachable hosts, resulting in SSRF or open-proxy behavior. This issue affects Apache Kyuubi: from 1.8.0 before 1.12.0. Users are recommended to upgrade to version 1.12.0, which disables the proxy by default. To restore proxied Engine UI, set kyuubi.frontend.rest.engine.ui.proxy.enabled=true and configure allowed target hosts with kyuubi.frontend.rest.engine.ui.proxy.hosts.
Frequently asked questions
- What is CVE-2026-23904?
- Kyuubi Engine UI proxy accepts a host and port from the request path and proxies HTTP requests to that destination. A remote requester with network access to the proxy can cause the Kyuubi server to send HTTP requests to arbitrary reachable hosts, resulting in SSRF or open-proxy behavior. This issue affects Apache Kyuubi: from 1.8.0 before 1.12.0. Users are recommended to upgrade to version 1.12.0, which disables the proxy by default. To restore proxied Engine UI, set kyuubi.frontend.rest.engine.ui.proxy.enabled=true and configure allowed target hosts with kyuubi.frontend.rest.engine.ui.proxy.hosts.
- How severe is CVE-2026-23904?
- CVE-2026-23904 has a CVSS 3.x base score of 7.3, rated high severity. It is exploitable over network with low attack complexity, requires no privileges and no user interaction. Impact on confidentiality is low, integrity low, and availability low.
- Is CVE-2026-23904 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 1% (49th percentile), an estimate of the probability of exploitation in the next 30 days.
- What products are affected by CVE-2026-23904?
- CVE-2026-23904 affects Apache Kyuubi. See the affected-products list for the exact vulnerable versions.
- How do I fix CVE-2026-23904?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround. Given its high severity, prioritise patching exposed systems.
- When was CVE-2026-23904 published?
- CVE-2026-23904 was published on 2026-07-29 and last updated on 2026-08-05.
References
- https://github.com/apache/kyuubi/pull/7483
- https://lists.apache.org/thread/ps79fcfx49ox9kwgztc5t5bw0tyhck9m
- http://www.openwall.com/lists/oss-security/2026/07/29/3
Affected products (1)
- cpe:2.3:a:apache:kyuubi:*:*:*:*:*:*:*:*
More vulnerabilities in Apache Kyuubi
- CVE-2026-52680 — Critical (CVSS 9.8): Apache Kyuubi REST batch multipart upload handling uses the client-supplied multipart filename when creating a…
- CVE-2025-66518 — High (CVSS 8.8): Any client who can access to Apache Kyuubi Server via Kyuubi frontend protocols can bypass server-side config…
- CVE-2026-62391 — High (CVSS 8.1): The security fix for CVE-2025-66518 is incomplete. Any client who can access to Apache Kyuubi Server via Kyuubi…
All CVEs affecting Apache Kyuubi →
Other CWE-923 vulnerabilities
- CVE-2019-17440 — Critical (CVSS 10.0): Improper restriction of communications to Log Forwarding Card (LFC) on PA-7000 Series devices with second-generation…
- CVE-2024-41889 — Critical (CVSS 9.8): Multiple Pimax products accept WebSocket connections from unintended endpoints. If this vulnerability is exploited,…
- CVE-2026-34205 — Critical (CVSS 9.6): Home Assistant is open source home automation software that puts local control and privacy first. Home Assistant apps…
- CVE-2023-28078 — Critical (CVSS 9.1): Dell OS10 Networking Switches running 10.5.2.x and above contain a vulnerability with zeroMQ when VLT is configured. A…
- CVE-2025-61939 — High (CVSS 8.8): An unused function in MicroServer can start a reverse SSH connection to a vendor registered domain, without mutual…
- CVE-2025-20261 — High (CVSS 8.8): A vulnerability in the SSH connection handling of Cisco Integrated Management Controller (IMC) for Cisco UCS B-Series,…