{"id":"PYSEC-2026-3442","details":"Authenticated SSRF in Gravitino JobManager allows server-side HTTP requests to internal network and cloud metadata endpoints via unvalidated job template URIs. A vulnerability in Apache Gravitino.\n\nThis issue affects Apache Gravitino: from 1.0.0 through 1.2.1.\n\nUsers are recommended to upgrade to version 1.3.0, which fixes the issue.","aliases":["CVE-2026-49876"],"modified":"2026-07-14T10:45:07.614538510Z","published":"2026-07-13T10:16:29.603Z","references":[{"type":"ADVISORY","url":"http://www.openwall.com/lists/oss-security/2026/07/13/2"},{"type":"ADVISORY","url":"https://lists.apache.org/thread/2ffkj771d6dp1okh2cdtody969hoo1zs"}],"affected":[{"package":{"name":"apache-gravitino","ecosystem":"PyPI","purl":"pkg:pypi/apache-gravitino"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"1.0.0"},{"fixed":"1.3.0"}]}],"versions":["1.0.0","1.0.1","1.0.1rc1","1.0.1rc2","1.1.0","1.1.0rc0","1.1.0rc1","1.1.0rc2","1.1.0rc3","1.1.0rc4","1.1.1","1.1.1rc1","1.1.1rc3","1.1.1rc4","1.2.0","1.2.0.dev0","1.2.0rc1","1.2.0rc10","1.2.0rc11","1.2.0rc2","1.2.0rc4","1.2.0rc5","1.2.0rc6","1.2.0rc7","1.2.0rc8","1.2.0rc9","1.2.1","1.2.1rc1","1.2.1rc2","1.3.0rc1","1.3.0rc2","1.3.0rc3","1.3.0rc4","1.3.0rc5","1.3.0rc6"],"ecosystem_specific":{},"database_specific":{"source":"https://github.com/pypa/advisory-database/blob/main/vulns/apache-gravitino/PYSEC-2026-3442.yaml"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"}]}