Server-Side Request Forgery Vulnerability in Kubeflow Pipelines by Kubeflow
CVE-2026-54745
10CRITICAL
What is CVE-2026-54745?
A vulnerability in the Kubeflow Pipelines frontend allows unauthenticated server-side request forgery. The issue lies in the /_proxy/ route, where an attacker can manipulate the _routePathWithReferer() function to forward requests to arbitrary HTTP or HTTPS targets. Since there's no host allowlist or filtering for sensitive address types, this can result in unauthorized access to internal services and expose critical information, including cloud metadata credentials. The vulnerability is fixed in version 2.17.0, but prior versions remain susceptible.
Affected Version(s)
pipelines < 2.17.0
