CVE-2026-49876

CVE-2026-49876: Apache Gravitino: Authenticated SSRF in Gravitino JobManager allows server-side HTTP requests to internal network and cloud metadata endpoints via unvalidated job template URIs

Vendor Apache Software Foundation
Product Apache Gravitino
Weakness CWE-918 · SSRF
Published July 13, 2026
Last update July 13, 2026

CVSS base score

What the vulnerability does

01Description

Authenticated SSRF in Gravitino JobManager allows server-side HTTP requests to internal network and cloud metadata endpoints via unvalidated job template URIs. A vulnerability in Apache Gravitino. This issue affects Apache Gravitino: from 1.0.0 through 1.2.1. Users are recommended to upgrade to version 1.3.0, which fixes the issue.

Key dates

02Disclosure timeline

July 13, 2026 CVE published
July 13, 2026 Record updated

Related vulnerabilities

04Related CVE