Server-Side Request Forgery Vulnerability in Kubeflow Pipelines by Kubeflow
CVE-2026-54745

10CRITICAL

Key Information:

Vendor

Kubeflow

Status
Vendor
CVE Published:
28 August 2026

What is CVE-2026-54745?

A vulnerability in the Kubeflow Pipelines frontend allows unauthenticated server-side request forgery. The issue lies in the /_proxy/ route, where an attacker can manipulate the _routePathWithReferer() function to forward requests to arbitrary HTTP or HTTPS targets. Since there's no host allowlist or filtering for sensitive address types, this can result in unauthorized access to internal services and expose critical information, including cloud metadata credentials. The vulnerability is fixed in version 2.17.0, but prior versions remain susceptible.

Affected Version(s)

pipelines < 2.17.0

References

CVSS V3.1

Score:
10
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.