CVE-2025-26866
Apache HugeGraph-Server: RAFT and deserialization vulnerability
CVSS Score
8.8
EPSS Score
0.0%
EPSS Percentile
0th
A remote code execution vulnerability exists where a malicious Raft node can exploit insecure Hessian deserialization within the PD store. The fix enforces IP-based authentication to restrict cluster membership and implements a strict class whitelist to harden the Hessian serialization process against object injection attacks. Users are recommended to upgrade to version 1.7.0, which fixes the issue.
| CWE | CWE-502 |
| Vendor | apache software foundation |
| Product | apache hugegraph-server |
| Published | Dec 12, 2025 |
| Last Updated | Feb 26, 2026 |
Stay Ahead of the Next One
Get instant alerts for apache software foundation apache hugegraph-server
Be the first to know when new high vulnerabilities affecting apache software foundation apache hugegraph-server are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Apache Software Foundation / Apache HugeGraph-Server
1.0.0 < 1.7.0
References
Credits
๐ shukuang ๐ yulate ๐ X1r0z haohao0103