HIGH 7.3 NVD
CVE-2026-23904
Kyuubi Engine UI proxy accepts a host and port from the request path and proxies HTTP requests to that destination. A remote requester with network access to th
Kyuubi Engine UI proxy accepts a host and port from the request path and proxies HTTP requests to that destination. A remote requester with network access to the proxy can cause the Kyuubi server to send HTTP requests to arbitrary reachable hosts, resulting in SSRF or open-proxy behavior.
This issue affects Apache Kyuubi: from 1.8.0 before 1.12.0.
Users are recommended to upgrade to version 1.12.0, which disables the proxy by default. To restore proxied Engine UI, set kyuubi.frontend.rest.engine.ui.proxy.enabled=true and configure allowed target hosts with kyuubi.frontend.rest.engine.ui.proxy.hosts.
References
- https://github.com/apache/kyuubi/pull/7483
- https://lists.apache.org/thread/ps79fcfx49ox9kwgztc5t5bw0tyhck9m
- http://www.openwall.com/lists/oss-security/2026/07/29/3
- https://www.openwall.com/lists/oss-security/2026/07/29/3
This high severity vulnerability with a CVSS score of 7.3 was published on 2026-07-29 via NVD.
vulnfeed aggregates 9166 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.