PT-2025-50223 · Apache · Apache Hugegraph-Server

·

CVE-2025-26866

·

Published

2025-12-09

·

Updated

2025-12-29

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Apache HugeGraph-Server versions prior to 1.7.0
Description A remote code execution issue exists where a malicious Raft node can exploit insecure Hessian deserialization within the PD store. The fix enforces IP-based authentication to restrict cluster membership and implements a strict class whitelist to harden the Hessian serialization process against object injection attacks. Hessian is a binary object serialization format.
Recommendations Upgrade to version 1.7.0 to resolve the issue.

Exploit

Fix

DoS

RCE

Deserialization of Untrusted Data

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-26866
GHSA-Q37J-3367-FWV7

Affected Products

Apache Hugegraph-Server