CVE-2025-32897

CRITICAL LAB

Apache Seata < 2.3.0 - Insecure Deserialization

Title source: rule

Description

Deserialization of Untrusted Data vulnerability in Apache Seata (incubating). This security vulnerability is the same as CVE-2024-47552, but the version range described in the CVE-2024-47552 definition is too narrow. This issue affects Apache Seata (incubating): from 2.0.0 before 2.3.0. Users are recommended to upgrade to version 2.3.0, which fixes the issue.

Exploits (1)

github WORKING POC 1 stars
by exploitintel · pythonpoc
https://github.com/exploitintel/eip-pocs-and-cves/tree/main/CVE-2025-32897

Scores

CVSS v3 9.8
EPSS 0.0031
EPSS Percentile 53.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Lab Environment

Lab screenshot
vulnerable
docker pull ghcr.io/exploitintel/cve-2025-32897-vulnerable:latest
All Labs GitHub

Classification

CWE
CWE-502
Status published

Affected Products (2)

apache/seata < 2.3.0
org.apache.seata/seata-config-core < 2.3.0Maven

Timeline

Published Jun 28, 2025
Tracked Since Feb 18, 2026