CVE-2025-9571 - CVE House
Back to Database
Status published High CVE-2025-9571

Arbitrary Code Execution in Google Cloud Data Fusion via Malicious Artifact Upload

Vulnerability Description

A remote code execution (RCE) vulnerability exists in Google Cloud Data Fusion. A user with permissions to upload artifacts to a Data Fusion instance can execute arbitrary code within the core AppFabric component. This could allow the attacker to gain control over the Data Fusion instance, potentially leading to unauthorized access to sensitive data, modification of data pipelines, and exploration of the underlying infrastructure. The following CDAP versions include the necessary update to protect against this vulnerability: * 6.10.6+ * 6.11.1+  Users must immediately upgrade to them, or greater ones, available at: https://github.com/cdapio/cdap-build/releases .

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-9571

Credits & Attribution

The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:

  • Tomas Lažauninkas

Affected Vendor

Google Cloud

View all reports →

Affected Software

Cloud Data Fusion
Vulnerable Versions:
0

Timeline

Official Publish: December 10th, 2025
Last Modified: December 10th, 2025
Added to House: July 22nd, 2026

CVSS Vectors

Weaknesses (CWE)