CVE-2025-32897 is a critical deserialization of untrusted data vulnerability (CWE-502) affecting Apache Seata (incubating) versions 2.0.0 through 2.2.x. It carries a CVSS v3.1 score of 9.8 (CRITICAL) due to its network-exploitable nature and high impact on confidentiality, integrity, and availability. However, the Apache Seata team assesses its real-world severity as Low, citing its isolation to the optional Raft cluster mode and the requirement for prior internal network access, as Seata typically operates within trusted internal environments. There is currently no evidence of active exploitation, nor are public exploit codes or Metasploit modules available, with minimal community discussion observed. Users are recommended to upgrade to version 2.3.0 to remediate this issue.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 2.0.0, < 2.3.0CPE matchmatch criteria | cpe:2.3:a:apache:seata:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.