Skip to content
kylinGHSA-f6m8-qm7j-fh65

Apache Kylin Server-Side Request Forgery (SSRF) Vulnerability

High7.3CVE-2025-61735 · Published Oct 2, 2025 · updated Nov 5, 2025

Server-Side Request Forgery (SSRF) vulnerability in Apache Kylin. This issue affects Apache Kylin: from 4.0.0 through 5.0.2. You are fine as long as the Kylin's system and project admin access is well protected. Users are recommended to upgrade to version 5.0.3, which fixes the issue.

GitHub advisory

Affected versions

PackageAffectedFixed in
org.apache.kylin:kylin
Maven
>= 4.0.0, < 5.0.35.0.3
Details and references

More kylin advisories

All kylin
Advisory
Apache Kylin Authentication Bypass Vulnerability
High7.5Oct 2, 2025
Apache Kylin Files or Directories Accessible to External Parties
High7.5Oct 2, 2025
Apache Kylin Code Injection via JDBC Configuration Alteration
LowMar 27, 2025
Apache Kylin Session Fixation vulnerability
High9.1Nov 4, 2024
Apache Kylin vulnerable to Command injection by Useless configuration
High8.8Dec 30, 2022
Authentication bypass in Apache Kylin
Medium5.3Feb 10, 2022

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.