CVE-2026-54745: Kubeflow Pipelines enables users to build and deploy portable, scalable machine learning workflows. Prior to 2.17.0, the
Summary
Kubeflow Pipelines (a tool for building machine learning workflows) before version 2.17.0 has a server-side request forgery vulnerability (SSRF, a bug where an attacker tricks the server into making requests to internal systems it shouldn't access) in its frontend. An attacker can use the /_proxy/ route to make the server send requests to internal services and steal sensitive data like cloud credentials or Kubernetes API access, even without authentication.
Solution / Mitigation
Update to Kubeflow Pipelines version 2.17.0 or later.
Vulnerability Details
10(critical)
EPSS: 0.0%
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
network
low
none
none
August 28, 2026
Classification
Taxonomy References
Affected Vendors
Related Issues
CVE-2026-63086: text-generation-inference through 3.3.7 contains a server-side request forgery (SSRF) vulnerability in the OpenAI-compat
CVE-2026-34371: LibreChat is a ChatGPT clone with additional features. Prior to 0.8.4, LibreChat trusts the name field returned by the e
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-54745
First tracked: August 28, 2026 at 08:08 PM
Classified by LLM (prompt v3) · confidence: 92%