CVE-2025-62233 - CVE House
Back to Database
Status published Unknown CVE-2025-62233

Apache DolphinScheduler: Deserialization of untrusted data in RPC

Vulnerability Description

Deserialization of Untrusted Data vulnerability in Apache DolphinScheduler RPC module. This issue affects Apache DolphinScheduler:  Version >= 3.2.0 and < 3.3.1. Attackers who can access the Master or Worker nodes can compromise the system by creating a StandardRpcRequest, injecting a malicious class type into it, and sending RPC requests to the DolphinScheduler Master/Worker nodes. Users are recommended to upgrade to version [3.3.1], which fixes the issue.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-62233

Credits & Attribution

The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:

  • 75Acol, fcgboy, ch0wn, zer0duck

Affected Vendor

Apache Software Foundation

View all reports →

Affected Software

Apache DolphinScheduler
Vulnerable Versions:
3.2.0

Timeline

Official Publish: April 24th, 2026
Last Modified: April 24th, 2026
Added to House: July 22nd, 2026

CVSS Vectors

No vector data available

Weaknesses (CWE)