PT-2025-50223 · Apache · Apache Hugegraph-Server

Haohao0103

+3

·

Published

2025-12-09

·

Updated

2025-12-29

·

CVE-2025-26866

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Apache HugeGraph-Server versions prior to 1.7.0
Description A remote code execution issue exists where a malicious Raft node can exploit insecure Hessian deserialization within the PD store. The fix enforces IP-based authentication to restrict cluster membership and implements a strict class whitelist to harden the Hessian serialization process against object injection attacks. Hessian is a binary object serialization format.
Recommendations Upgrade to version 1.7.0 to resolve the issue.

Fix

RCE

Deserialization of Untrusted Data

Weakness Enumeration

Related Identifiers

CVE-2025-26866
GHSA-Q37J-3367-FWV7

Affected Products

Apache Hugegraph-Server