{
  "from_raw": "Akira Ajisaka <aajisaka@apache.org>",
  "from": "Akira Ajisaka <aa...@apache.org>",
  "gravatar": "b1835b72f50e06c231765827942b281e",
  "to": "an...@apache.org,\n de...@kyuubi.apache.org",
  "subject": "CVE-2026-62391: Apache Kyuubi: kyuubi.session.local.dir.allow.list bypass via unprefixed Spark file-conf aliases",
  "message-id": "<acb8c0e8-5544-b710-54a3-937087a31fc5@apache.org>",
  "mid": "ftythvbr35cwtllykfm6k3xdz6bzhtz5",
  "permalinks": [
    "ftythvbr35cwtllykfm6k3xdz6bzhtz5",
    "rdd75705b0c60c468049a9d880106aeecd26f47d37559cfec68fc89c1@<announce.apache.org>"
  ],
  "dbid": "780e3cc5af11c56f94bf3f5e9a40c3c8ba86e0ad394c803d57aad2e347ed1b45",
  "cc": "de...@kyuubi.apache.org",
  "epoch": 1785489569,
  "list": "<announce.apache.org>",
  "list_raw": "<announce.apache.org>",
  "date": "2026/07/31 09:19:29",
  "private": false,
  "references": "",
  "in-reply-to": "",
  "body": "Severity: important \n\nAffected versions:\n\n- Apache Kyuubi (org.apache.kyuubi:kyuubi-server) 1.6.0 before 1.12.0\n\nDescription:\n\nThe security fix for CVE-2025-66518 is incomplete.\u00a0Any client who can access to Apache Kyuubi Server via Kyuubi frontend protocols can bypass server-side config\u00a0kyuubi.session.local.dir.allowlist via unprefixed Spark config aliases.\n\nThis issue affects Apache Kyuubi: from 1.6.0 before 1.12.0.\n\nUsers are recommended to upgrade to version 1.12.0, which fixes the issue.\n\nCredit:\n\nAnand Nalya (finder)\n\nReferences:\n\nhttps://kyuubi.apache.org\nhttps://www.cve.org/CVERecord?id=CVE-2026-62391\n\n",
  "body_short": "Severity: important \n\nAffected versions:\n\n- Apache Kyuubi (org.apache.kyuubi:kyuubi-server) 1.6.0 before 1.12.0\n\nDescription:\n\nThe security fix for CVE-2025-66518 is incomplete.\u00a0Any client who can acce",
  "html_source_only": false,
  "attachments": [],
  "forum": "announce@apache.org",
  "size": 3193,
  "id": "ftythvbr35cwtllykfm6k3xdz6bzhtz5"
}