Every CVE whose affected-product data names Apache Kyuubi, ordered by CVSS severity, with EPSS exploit prediction and CISA KEV status.
CVEs (4)
CVE-2026-52680 — CVSS 9.8 (critical): Apache Kyuubi REST batch multipart upload handling uses the client-supplied multipart filename when creating a temporary uploaded resource…
CVE-2025-66518 — CVSS 8.8 (high): Any client who can access to Apache Kyuubi Server via Kyuubi frontend protocols can bypass server-side config kyuubi.session.local.dir.allow…
CVE-2026-62391 — CVSS 8.1 (high): The security fix for CVE-2025-66518 is incomplete. Any client who can access to Apache Kyuubi Server via Kyuubi frontend protocols can…
CVE-2026-23904 — CVSS 7.3 (high): Kyuubi Engine UI proxy accepts a host and port from the request path and proxies HTTP requests to that destination. A remote requester with…