Deserialization Vulnerability in Apache Jackrabbit Core and JCR Commons
CVE-2025-58782
Key Information:
- Vendor
Apache
- Vendor
- CVE Published:
- 8 September 2025
What is CVE-2025-58782?
A deserialization of untrusted data vulnerability exists in both Apache Jackrabbit Core and JCR Commons, affecting versions from 1.0.0 through 2.22.1. Deployments that process JNDI URIs for JCR lookup from untrusted users are susceptible to malicious JNDI references. This security flaw can enable attackers to execute arbitrary code through unsafe data deserialization. Users are advised to upgrade to version 2.22.2, where JNDI lookup capability has been disabled by default. Users leveraging this feature are encouraged to assess their use of JNDI URIs for JCR lookup.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Apache Jackrabbit Core 1.0.0 <= 2.22.1
Apache Jackrabbit JCR Commons 1.0.0 <= 2.22.1
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved