CVE-2025-62233

CVE-2025-62233: Apache DolphinScheduler: Deserialization of untrusted data in RPC

Vendor Apache Software Foundation
Product Apache DolphinScheduler
Weakness CWE-502 · Unsafe deserialization
Published April 24, 2026
Last update April 24, 2026

CVSS base score

What the vulnerability does

Description

Deserialization of Untrusted Data vulnerability in Apache DolphinScheduler RPC module. This issue affects Apache DolphinScheduler:  Version >= 3.2.0 and < 3.3.1. Attackers who can access the Master or Worker nodes can compromise the system by creating a StandardRpcRequest, injecting a malicious class type into it, and sending RPC requests to the DolphinScheduler Master/Worker nodes. Users are recommended to upgrade to version [3.3.1], which fixes the issue.

Key dates

Disclosure timeline

April 24, 2026 CVE published
April 24, 2026 Record updated