CVE-2025-32897

Severity
9.8CRITICAL
EPSS
0.3%
top 48.31%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 28

Description

Deserialization of Untrusted Data vulnerability in Apache Seata (incubating). This security vulnerability is the same as CVE-2024-47552, but the version range described in the CVE-2024-47552 definition is too narrow. This issue affects Apache Seata (incubating): from 2.0.0 before 2.3.0. Severity Justification: The Apache Seata security team assesses the severity of this vulnerability as "Low" due to stringent real-world mitigating factors. First, the vulnerability is strictly isolated to the R

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages3 packages

NVDapache/seata2.0.02.3.0
Mavenorg.apache.seata:seata-config-core2.0.02.3.0

🔴Vulnerability Details

3
GHSA
Apache Seata Vulnerable to Deserialization of Untrusted Data2025-06-28
OSV
Apache Seata Vulnerable to Deserialization of Untrusted Data2025-06-28
CVEList
Apache Seata (incubating): Deserialization of untrusted Data in Apache Seata Server2025-06-28
CVE-2025-32897 (CRITICAL CVSS 9.8) | Deserialization of Untrusted Data v | cvebase.io