Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2025-26866— Apache HugeGraph-Server: RAFT and deserialization vulnerability

EPSS 1.69% · P82
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2025-26866

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Apache HugeGraph-Server: RAFT and deserialization vulnerability
Source: NVD (National Vulnerability Database)
Vulnerability Description
A remote code execution vulnerability exists where a malicious Raft node can exploit insecure Hessian deserialization within the PD store. The fix enforces IP-based authentication to restrict cluster membership and implements a strict class whitelist to harden the Hessian serialization process against object injection attacks. Users are recommended to upgrade to version 1.7.0, which fixes the issue.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
可信数据的反序列化
Source: NVD (National Vulnerability Database)
Vulnerability Title
Apache HugeGraph-Server 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Apache HugeGraph-Server是Apache基金会的一个图数据库的服务端进程。 Apache HugeGraph-Server存在安全漏洞,该漏洞源于PD存储中不安全的Hessian反序列化,可能导致远程代码执行。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
Apache Software FoundationApache HugeGraph-Server 1.0.0 ~ 1.7.0 -

II. Public POCs for CVE-2025-26866

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2025-26866

登录查看更多情报信息。

Same Patch Batch · Apache Software Foundation · 2025-12-12 · 7 CVEs total

CVE-2025-53960Apache StreamPark: Uses the user’s password as the secret key
CVE-2025-54947Apache StreamPark: Use hard-coded key vulnerability
CVE-2025-54981Apache StreamPark: Weak Encryption Algorithm in StreamPark
CVE-2025-58137Apache Fineract: IDOR via self-service API
CVE-2025-58130Apache Fineract: Server Key not masked
CVE-2025-23408Apache Fineract: weak password policy

IV. Related Vulnerabilities

V. Comments for CVE-2025-26866

No comments yet


Leave a comment