Threat Advisory

eKuiper Vulnerabilities Impact APIs and Access Cloud Metadata

Threat: Vulnerability
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: Medium
[subscribe_to_unlock_form]


EXECUTIVE SUMMARY:

Multiple vulnerabilities affecting eKuiper have been identified. These vulnerabilities pose a medium risk and can be exploited by attackers with permissions to register external services or create rules, allowing them to induce the eKuiper server to make requests to unintended network locations.[/subscribe_to_unlock_form]


EXECUTIVE SUMMARY:

Multiple vulnerabilities affecting eKuiper have been identified. These vulnerabilities pose a medium risk and can be exploited by attackers with permissions to register external services or create rules, allowing them to induce the eKuiper server to make requests to unintended network locations.[emaillocker id="1283"]

CVE-2025-24979 (CVSS 5.5 — Medium): A Server-Side Request Forgery (SSRF) vulnerability in eKuiper allows an attacker with permissions to register external services or create rules to induce the eKuiper server to make requests to unintended network locations, such as internal services, loopback interfaces (localhost), or cloud metadata endpoints.

CVE-2025-58363 (CVSS 5.5 — Medium): A path traversal vulnerability in eKuiper's administrative management endpoints allows privileged users or attackers with access to management APIs to delete arbitrary files or directories on the host system.

 

RECOMMENDATIONS:

 

REFERENCES:

The following reports contain further technical details:
https://github.com/advisories/GHSA-pqqc-8v73-9gg2
https://github.com/advisories/GHSA-c23q-fw86-9h5x

[/emaillocker]
crossmenu