Deserialization of Untrusted Data in Apache Software's Seata
CVE-2025-32897
Currently unrated
What is CVE-2025-32897?
A deserialization of untrusted data vulnerability exists in Apache Seata, affecting versions prior to 2.3.0. This issue mirrors that of CVE-2024-47552, but with a broader range of affected versions. Users are advised to update to version 2.3.0 to effectively address the security risk.
Affected Version(s)
Apache Seata (incubating) 2.0.0 < 2.3.0