« Back to list

Apache

Apache Kyuubi: vulnerabilities and CVEs

Apache Kyuubi has 4 published vulnerabilities, 4 of them in the last 12 months. 1 are rated critical and 0 are listed by CISA as actively exploited.

CVEs4
Last 12 months4
Critical1
Actively exploited0

All vulnerabilities in the catalogue →⭐ Follow this technology

Latest vulnerabilities

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2026-62391High (8.1)0.79%—Jul 31, 2026
The security fix for CVE-2025-66518 is incomplete. Any client who can access to Apache Kyuubi Server via Kyuubi frontend protocols can bypass server-side config kyuubi.session.local.dir.allowlist via unprefixed Spark…
CVE-2026-52680Critical (9.8)1.1%—Jul 30, 2026
Apache Kyuubi REST batch multipart upload handling uses the client-supplied multipart filename when creating a temporary uploaded resource. A remote attacker who can access the REST batch upload endpoint can provide…
CVE-2026-23904High (7.3)0.85%—Jul 29, 2026
Kyuubi Engine UI proxy accepts a host and port from the request path and proxies HTTP requests to that destination. A remote requester with network access to the proxy can cause the Kyuubi server to send HTTP requests…
CVE-2025-66518High (8.8)1.00%—Jan 5, 2026
Any client who can access to Apache Kyuubi Server via Kyuubi frontend protocols can bypass server-side config kyuubi.session.local.dir.allow.list and use local files which are not listed in the config. This issue…

🎯 How it gets exploited (ATT&CK techniques)

  1. T1005 Data from Local System2
  2. T1190 Exploit Public-Facing Application2
  3. T1090 Proxy1
  4. T1203 Exploitation for Client Execution1
  5. T1210 Exploitation of Remote Services1
  6. T1565.002 Transmitted Data Manipulation1

Number of CVEs of this technology mapped to each exploitation or primary-impact technique.

📰 Related news

Other products by Apache