Database/Control plane, storage & DevOps

Kubeflow Pipelines (frontend server, /_proxy/ route in proxy-middleware.ts): The Kubeflow Pipelines frontend forwards
Impact
The Kubeflow Pipelines frontend forwards arbitrary user-supplied URLs through /_proxy/ with no allowlist, no IP filter and no auth gate, and the route is not covered by the auth middleware - so it stays open even with ENABLE_AUTHZ=true, the posture documented as multi-user secure. Method, body and headers pass through verbatim, giving an unauthenticated caller reach into link-local metadata (169.254.0.0/16), loopback, RFC1918 and any *.svc.cluster.local service, plus an HTTP smuggling primitive against them. On a GPU cluster the first stop is node IAM credentials.
Who can reach it
Anyone who can reach the Kubeflow Pipelines frontend, including via a crafted Referer header on unrelated paths. No credentials, and multi-user mode does not help.
What to do
Track the kubeflow/pipelines advisory and upgrade the frontend image once a fixed tag ships. Until then, block the four /_proxy/ prefixes (/apis/v1beta1/_proxy/, /apis/v2beta1/_proxy/, and their /pipeline-prefixed forms) at the ingress, and rotate node/pod cloud credentials if the frontend was reachable from untrusted networks.
References
Related entries
- Kubeflow Pipelines (frontend server, /_proxy/ route in proxy-middleware.ts): The Kubeflow Pipelines frontend forwardsNCVD-2026-040-kubeflow-pipelines-frontend-serv · Kubeflow Pipelines (frontend server, /_proxy/ route in proxy-middleware.ts)Unscored
- HPE iLO4: Authentication bypass and remote code execution — the "29 A's" `Connection` header bugCVE-2017-12542 · HPE iLO4Critical
- Cisco ACI Multi-Site Orchestrator (Application Services Engine): Complete unauthenticated authentication bypass on theCVE-2021-1388 · Cisco ACI Multi-Site Orchestrator (Application Services Engine)Critical
- GitLab: Image files passed unvalidated to a file parser (ExifTool)CVE-2021-22205 · GitLabCritical
- Eaton Intelligent Power Manager (IPM) prior to 1.69: Unauthenticated remote code execution on Eaton's power-managementCVE-2021-23281 · Eaton Intelligent Power Manager (IPM) prior to 1.69Critical
- Redis: Debian/Ubuntu packaging leaves a Lua sandbox escapeCVE-2022-0543 · RedisCritical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.