{"id":"GHSA-f8r6-6222-9pvc","summary":"Apache Kyuubi Server vulnerable to Path Traversal","details":"Any client who can access to Apache Kyuubi Server via Kyuubi frontend protocols can bypass server-side config kyuubi.session.local.dir.allow.list and use local files which are not listed in the config.\n\nThis issue affects Apache Kyuubi: from 1.6.0 through 1.10.2.\n\nUsers are recommended to upgrade to version 1.10.3 or upper, which fixes the issue.","aliases":["CVE-2025-66518"],"modified":"2026-02-03T03:04:45.440485Z","published":"2026-01-05T09:30:19Z","database_specific":{"nvd_published_at":"2026-01-05T09:15:54Z","cwe_ids":["CWE-22","CWE-27"],"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2026-01-05T19:57:06Z"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-66518"},{"type":"PACKAGE","url":"https://github.com/apache/kyuubi"},{"type":"WEB","url":"https://lists.apache.org/thread/xp460bwbyzdhho34ljd4nchyt2fmhodl"},{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2026/01/05/1"}],"affected":[{"package":{"name":"org.apache.kyuubi:kyuubi-server_2.12","ecosystem":"Maven","purl":"pkg:maven/org.apache.kyuubi/kyuubi-server_2.12"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"1.6.0"},{"fixed":"1.10.3"}]}],"versions":["1.10.0","1.10.1","1.10.2","1.6.0-incubating","1.6.1-incubating","1.7.0","1.7.1","1.7.2","1.7.3","1.7.4","1.8.0","1.8.1","1.8.2","1.8.3","1.9.0","1.9.1","1.9.2","1.9.3","1.9.4"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/01/GHSA-f8r6-6222-9pvc/GHSA-f8r6-6222-9pvc.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:P/VC:H/VI:H/VA:L/SC:H/SI:H/SA:L"}]}