CVE-2025-64408

CVE-2025-64408: Apache Causeway: Java deserialization vulnerability to authenticated attackers

Vendor Apache Software Foundation
Product Apache Causeway
Weakness CWE-502 · Unsafe deserialization
Published November 19, 2025
Last update February 26, 2026

CVSS base score

What the vulnerability does

Description

Apache Causeway faces Java deserialization vulnerabilities that allow remote code execution (RCE) through user-controllable URL parameters. These vulnerabilities affect all applications using Causeway's ViewModel functionality and can be exploited by authenticated attackers to execute arbitrary code with application privileges.  This issue affects all current versions. Users are recommended to upgrade to version 3.5.0, which fixes the issue.

Key dates

Disclosure timeline

November 19, 2025 CVE published
February 26, 2026 Record updated