Apache Kyuubi Server vulnerable to Path Traversal
High severity
GitHub Reviewed
Published
Jan 5, 2026
to the GitHub Advisory Database
•
Updated Jan 29, 2026
Package
Affected versions
>= 1.6.0, < 1.10.3
Patched versions
1.10.3
Description
Published by the National Vulnerability Database
Jan 5, 2026
Published to the GitHub Advisory Database
Jan 5, 2026
Reviewed
Jan 5, 2026
Last updated
Jan 29, 2026
Any client who can access to Apache Kyuubi Server via Kyuubi frontend protocols can bypass server-side config kyuubi.session.local.dir.allow.list and use local files which are not listed in the config.
This issue affects Apache Kyuubi: from 1.6.0 through 1.10.2.
Users are recommended to upgrade to version 1.10.3 or upper, which fixes the issue.
References