CVE-2025-68637

CRITICAL

Apache Uniffle < 0.10.0 - Man-in-the-Middle via Disabled SSL Certificate Validation

Title source: llm
STIX 2.1

Description

The Uniffle HTTP client is configured to trust all SSL certificates and disables hostname verification by default. This insecure configuration exposes all REST API communication between the Uniffle CLI/client and the Uniffle Coordinator service to potential Man-in-the-Middle (MITM) attacks. This issue affects all versions from before 0.10.0. Users are recommended to upgrade to version 0.10.0, which fixes the issue.

References (2)

Core 2
Core References
Mailing List, Vendor Advisory, Issue Tracking vendor-advisory
https://lists.apache.org/thread/trvdd11hmpbjno3t8rc9okr4t036ox2v
Mailing List, Third Party Advisory
http://www.openwall.com/lists/oss-security/2025/12/27/2

Scores

CVSS v3 9.1
EPSS 0.0007
EPSS Percentile 22.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-297
Status published
Products (1)
apache/uniffle < 0.10.0
Published Jan 07, 2026
Tracked Since Feb 18, 2026