CVE-2025-68637

CVE-2025-68637: Apache Uniffle: Insecure SSL Configuration in Uniffle HTTP Client

Vendor Apache Software Foundation
Product Apache Uniffle
Weakness CWE-297
Published January 7, 2026
Last update January 7, 2026

CVSS base score

What the vulnerability does

Description

The Uniffle HTTP client is configured to trust all SSL certificates and disables hostname verification by default. This insecure configuration exposes all REST API communication between the Uniffle CLI/client and the Uniffle Coordinator service to potential Man-in-the-Middle (MITM) attacks. This issue affects all versions from before 0.10.0. Users are recommended to upgrade to version 0.10.0, which fixes the issue.

Key dates

Disclosure timeline

January 7, 2026 CVE published
January 7, 2026 Record updated