Apache Seata Deserialization of Untrusted Data Vulnerability

Vulnerability

A deserialization of untrusted data vulnerability has been identified in Apache Seata (incubating) version 2.4.0. This vulnerability allows for potential exploitation through improper handling of serialized data, which could lead to unintended consequences.

Impact

Exploitation of this vulnerability could allow for deserialization attacks, where an attacker manipulates serialized data to execute arbitrary code or cause other harmful effects on the application.

Remediation

Users are advised to upgrade to Apache Seata version 2.5.0, which addresses this vulnerability.

Added: Aug 8, 2025, 10:17 AM
Updated: Aug 8, 2025, 10:17 AM

Vulnerability Rating

Custom Algorithm
spread
1.4
impact
10.0
exploitability
7.0
remediation
7.7
relevance
0.3
threat
0.0
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.