Apache Hugegraph vulnerabilities

4 known vulnerabilities affecting apache/hugegraph.

Total CVEs
4
CISA KEV
1
actively exploited
Public exploits
2
Exploited in wild
1
Severity breakdown
CRITICAL3HIGH1

Vulnerabilities

Page 1 of 1
CVE-2025-26866HIGHCVSS 8.8≥ 1.0.0, < 1.7.02025-12-12
CVE-2025-26866 [HIGH] CWE-502 CVE-2025-26866: A remote code execution vulnerability exists where a malicious Raft node can exploit insecure Hessia A remote code execution vulnerability exists where a malicious Raft node can exploit insecure Hessian deserialization within the PD store. The fix enforces IP-based authentication to restrict cluster membership and implements a strict class whitelist to harden the Hessian serialization process against object injection attacks. Users are recommended
nvd
CVE-2024-43441CRITICALCVSS 9.8PoC≥ 1.0.0, < 1.5.02024-12-24
CVE-2024-43441 [CRITICAL] CWE-302 CVE-2024-43441: Authentication Bypass by Assumed-Immutable Data vulnerability in Apache HugeGraph-Server. This issu Authentication Bypass by Assumed-Immutable Data vulnerability in Apache HugeGraph-Server. This issue affects Apache HugeGraph-Server: from 1.0.0 before 1.5.0. Users are recommended to upgrade to version 1.5.0, which fixes the issue.
nvd
CVE-2024-27348CRITICALCVSS 9.8KEVPoC≥ 1.0.0, < 1.3.02024-04-22
CVE-2024-27348 [CRITICAL] CWE-284 CVE-2024-27348: RCE-Remote Command Execution vulnerability in Apache HugeGraph-Server.This issue affects Apache Huge RCE-Remote Command Execution vulnerability in Apache HugeGraph-Server.This issue affects Apache HugeGraph-Server: from 1.0.0 before 1.3.0 in Java8 & Java11 Users are recommended to upgrade to version 1.3.0 with Java11 & enable the Auth system, which fixes the issue.
nvd
CVE-2024-27349CRITICALCVSS 9.1≥ 1.0.0, < 1.3.02024-04-22
CVE-2024-27349 [CRITICAL] CWE-290 CVE-2024-27349: Authentication Bypass by Spoofing vulnerability in Apache HugeGraph-Server.This issue affects Apache Authentication Bypass by Spoofing vulnerability in Apache HugeGraph-Server.This issue affects Apache HugeGraph-Server: from 1.0.0 before 1.3.0. Users are recommended to upgrade to version 1.3.0, which fixes the issue.
nvd