Executive brief
Kubeflow Pipelines is a platform for building and deploying machine learning workflows on Kubernetes. An unauthenticated attacker can exploit a server-side request forgery vulnerability in the frontend proxy endpoint to access internal services, cloud metadata credentials, and Kubernetes APIs without authorization, potentially exposing sensitive data or enabling unauthorized cluster modification.
Technical details
The vulnerability is a server-side request forgery (SSRF) in the /_proxy/ route of the frontend/server/proxy-middleware.ts component. The _routePathWithReferer() function accepts arbitrary attacker-controlled HTTP/HTTPS targets and passes them to createProxyMiddleware without validating the destination against a host allowlist or filtering for loopback, link-local, RFC1918, or cluster-local addresses. The route bypasses authorization middleware when ENABLE_AUTHZ=true and is accessible via multiple paths including /apis/v1beta1/_proxy/, /apis/v2beta1/_proxy/, /pipeline/apis/v1beta1/_proxy/, and /pipeline/apis/v2beta1/_proxy/, including through crafted Referer headers. An unauthenticated attacker can forward arbitrary HTTP methods, headers (Authorization, Cookie, X-Forwarded-For), and POST bodies to any reachable internal service and retrieve the upstream response. This is fixed in version 2.17.0.
Affected products
- Kubeflow Pipelines before 2.17.0
Timeline
- 2026-08-28: disclosed: Published to NVD
- 2026-06-10: patched: Fixed in version 2.17.0