This issue affects Apache Kyuubi: from 1.6.0 through 1.10.2.
Users are recommended to upgrade to version 1.10.3 or upper, which fixes the issue.
No analysis available yet.
No remediation available yet.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-f8r6-6222-9pvc | Apache Kyuubi Server vulnerable to Path Traversal |
Tue, 27 Jan 2026 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-22 | |
| CPEs | cpe:2.3:a:apache:kyuubi:*:*:*:*:*:*:*:* | |
| Metrics |
cvssV3_1
|
Tue, 06 Jan 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Apache
Apache kyuubi |
|
| Vendors & Products |
Apache
Apache kyuubi |
Tue, 06 Jan 2026 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 05 Jan 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Mon, 05 Jan 2026 09:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Any client who can access to Apache Kyuubi Server via Kyuubi frontend protocols can bypass server-side config kyuubi.session.local.dir.allow.list and use local files which are not listed in the config. This issue affects Apache Kyuubi: from 1.6.0 through 1.10.2. Users are recommended to upgrade to version 1.10.3 or upper, which fixes the issue. | |
| Title | Apache Kyuubi: Unauthorized directory access due to missing path normalization | |
| Weaknesses | CWE-27 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: apache
Published:
Updated: 2026-01-05T20:27:07.472Z
Reserved: 2025-12-04T01:47:50.401Z
Link: CVE-2025-66518
Updated: 2026-01-05T12:06:18.095Z
Status : Analyzed
Published: 2026-01-05T09:15:54.430
Modified: 2026-01-27T21:32:32.140
Link: CVE-2025-66518
No data.
OpenCVE Enrichment
Updated: 2026-01-06T14:17:38Z
Github GHSA