Skip to main content

Vendor/product archive

apache / hugegraph CVEs

Beta · best-effort

4 CVEs tagged to apache / hugegraph3 Critical, 1 High, 0 Medium, 0 Low, 0 Unrated.

CVE-2025-26866

Published Dec 12, 2025

A remote code execution vulnerability exists where a malicious Raft node can exploit insecure Hessian deserialization within the PD store. The fix enforces IP-based authentication…

CVSS 8.8 · High
evidence mentions
3
Buzz score
25.4
Vendor/product tagsBeta · best-effort

CVE-2024-43441

Published Dec 24, 2024

Authentication Bypass by Assumed-Immutable Data vulnerability in Apache HugeGraph-Server. This issue affects Apache HugeGraph-Server: from 1.0.0 before 1.5.0. Users are recommen…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-27349

Published Apr 22, 2024

Authentication Bypass by Spoofing vulnerability in Apache HugeGraph-Server.This issue affects Apache HugeGraph-Server: from 1.0.0 before 1.3.0. Users are recommended to upgrade t…

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-27348

Published Apr 22, 2024

RCE-Remote Command Execution vulnerability in Apache HugeGraph-Server.This issue affects Apache HugeGraph-Server: from 1.0.0 before 1.3.0 in Java8 & Java11 Users are recommended…

CVSS 9.8 · Critical
evidence mentions
3
Buzz score
50.4
KEV listed
Vendor/product tagsBeta · best-effort
Showing 1-4 of 4 CVEsPage 1 of 1