CVE-2025-26866

CVE-2025-26866: Apache HugeGraph-Server: RAFT and deserialization vulnerability

Vendor Apache Software Foundation
Product Apache HugeGraph-Server
Weakness CWE-502 · Unsafe deserialization
Published December 12, 2025
Last update February 26, 2026

CVSS base score

What the vulnerability does

Description

A remote code execution vulnerability exists where a malicious Raft node can exploit insecure Hessian deserialization within the PD store. The fix enforces IP-based authentication to restrict cluster membership and implements a strict class whitelist to harden the Hessian serialization process against object injection attacks. Users are recommended to upgrade to version 1.7.0, which fixes the issue.

Key dates

Disclosure timeline

December 12, 2025 CVE published
February 26, 2026 Record updated