Apache Hugegraph vulnerabilities
4 known vulnerabilities affecting apache/hugegraph.
Total CVEs
4
CISA KEV
1
actively exploited
Public exploits
2
Exploited in wild
1
Severity breakdown
CRITICAL3HIGH1
Vulnerabilities
Page 1 of 1
CVE-2025-26866HIGHCVSS 8.8≥ 1.0.0, < 1.7.02025-12-12
CVE-2025-26866 [HIGH] CWE-502 CVE-2025-26866: A remote code execution vulnerability exists where a malicious Raft node can exploit insecure Hessia
A remote code execution vulnerability exists where a malicious Raft node can exploit insecure Hessian deserialization within the PD store. The fix enforces IP-based authentication to restrict cluster membership and implements a strict class whitelist to harden the Hessian serialization process against object injection attacks.
Users are recommended
nvd
CVE-2024-43441CRITICALCVSS 9.8PoC≥ 1.0.0, < 1.5.02024-12-24
CVE-2024-43441 [CRITICAL] CWE-302 CVE-2024-43441: Authentication Bypass by Assumed-Immutable Data vulnerability in Apache HugeGraph-Server.
This issu
Authentication Bypass by Assumed-Immutable Data vulnerability in Apache HugeGraph-Server.
This issue affects Apache HugeGraph-Server: from 1.0.0 before 1.5.0.
Users are recommended to upgrade to version 1.5.0, which fixes the issue.
nvd
CVE-2024-27348CRITICALCVSS 9.8KEVPoC≥ 1.0.0, < 1.3.02024-04-22
CVE-2024-27348 [CRITICAL] CWE-284 CVE-2024-27348: RCE-Remote Command Execution vulnerability in Apache HugeGraph-Server.This issue affects Apache Huge
RCE-Remote Command Execution vulnerability in Apache HugeGraph-Server.This issue affects Apache HugeGraph-Server: from 1.0.0 before 1.3.0 in Java8 & Java11
Users are recommended to upgrade to version 1.3.0 with Java11 & enable the Auth system, which fixes the issue.
nvd
CVE-2024-27349CRITICALCVSS 9.1≥ 1.0.0, < 1.3.02024-04-22
CVE-2024-27349 [CRITICAL] CWE-290 CVE-2024-27349: Authentication Bypass by Spoofing vulnerability in Apache HugeGraph-Server.This issue affects Apache
Authentication Bypass by Spoofing vulnerability in Apache HugeGraph-Server.This issue affects Apache HugeGraph-Server: from 1.0.0 before 1.3.0.
Users are recommended to upgrade to version 1.3.0, which fixes the issue.
nvd