CVE-2022-41704 is a high-severity vulnerability in Apache Batik (prior to version 1.16) that allows attackers to execute arbitrary Java code by embedding it within a specially crafted SVG file. This unauthenticated remote code execution vulnerability has a CVSS score of 7.5, indicating a high potential for impact on confidentiality. While the vulnerability is significant, there is currently no evidence of active exploitation, publicly available exploit code, or notable community discussion surrounding it. Organizations using affected versions of Apache Batik are strongly advised to update to version 1.16 to mitigate this risk.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 1.0, < 1.16CPE matchmatch criteria | cpe:2.3:a:apache:batik:*:*:*:*:*:*:*:* | ||
10.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:* | ||
11.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Third-Party Package Updates in Splunk AppDynamics On-Premises Enterprise Console - August 2025
Aug 6, 2025Apache XML Graphics Batik vulnerable to code execution via SVG.
Oct 25, 2022batik: Apache XML Graphics Batik vulnerable to code execution via SVG
Oct 25, 2022