CVE-2026-54745: Kubeflow Pipelines enables users to build and deploy portable, scalable machine learning workflows. Prior to 2.17.0, the Kubeflow Pipelines frontend exposes an unauthenticated server-side request f...

Added to the CISA Known Exploited Vulnerabilities catalog on 28 Aug 2026. Vendor: AI/ML. Product: machine learning. CVSS score: 10.

Kubeflow Pipelines enables users to build and deploy portable, scalable machine learning workflows. Prior to 2.17.0, the Kubeflow Pipelines frontend exposes an unauthenticated server-side request forgery vulnerability through the /_proxy/ route in frontend/server/proxy-middleware.ts. The _routePa...

Required action: Review and patch if applicable to your AI infrastructure.