Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2025-50151

26
FAUCET Score

CVE-2025-50151 describes a critical vulnerability in Apache Jena versions up to 5.4.0, where administrator-uploaded configuration files allow unvalidated file access paths. This flaw carries a high CVSS score of 8.8, indicating that an authenticated attacker can achieve high impact on confidentiality, integrity, and availability with low attack complexity over the network. Currently, there is no public exploit code available, nor is there evidence of active exploitation or significant community discussion surrounding this vulnerability. Users are strongly advised to upgrade to Apache Jena version 5.5.0 to mitigate this risk.

Impacted Technologies

VendorProductVersion(s)CPE
< 5.5.0CPE matchmatch criteria
cpe:2.3:a:apache:jena:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

8.8HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
2.8
Impact Score
5.9
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.94%
Probability of exploitation in next 30 days
EPSS Percentile
57.2%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0094 is in the 52nd percentile among its peer group of 17,844 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (55)

mavenpatch availablevia ghsa
Product: org.apache.jena:jenaFixed in: 5.5.0
redhatvendor investigatingvia redhat_api
Product: AMQ ClientsFixed in: jena-arq
redhatvendor investigatingvia redhat_api
Product: AMQ ClientsFixed in: jena-base
redhatvendor investigatingvia redhat_api
Product: AMQ ClientsFixed in: jena-core
redhatvendor investigatingvia redhat_api
Product: AMQ ClientsFixed in: jena-iri
redhatvendor investigatingvia redhat_api
Product: AMQ ClientsFixed in: jena-shaded-guava
redhatvendor investigatingvia redhat_api
Product: Red Hat build of Apicurio Registry 3Fixed in: jena-base
redhatvendor investigatingvia redhat_api
Product: Red Hat build of Apicurio Registry 3Fixed in: jena-core
redhatvendor investigatingvia redhat_api
Product: Red Hat build of Apicurio Registry 3Fixed in: jena-iri
redhatvendor investigatingvia redhat_api
Product: Red Hat build of Apicurio Registry 3Fixed in: jena-shaded-guava
redhatvendor investigatingvia redhat_api
Product: Red Hat Data Grid 8Fixed in: jena-arq
redhatvendor investigatingvia redhat_api
Product: Red Hat Data Grid 8Fixed in: jena-base
redhatvendor investigatingvia redhat_api
Product: Red Hat Data Grid 8Fixed in: jena-core
redhatvendor investigatingvia redhat_api
Product: Red Hat Data Grid 8Fixed in: jena-iri
redhatvendor investigatingvia redhat_api
Product: Red Hat Data Grid 8Fixed in: jena-shaded-guava
redhatvendor investigatingvia redhat_api
Product: Red Hat JBoss Enterprise Application Platform 7Fixed in: jena-arq
redhatvendor investigatingvia redhat_api
Product: Red Hat JBoss Enterprise Application Platform 7Fixed in: jena-base
redhatvendor investigatingvia redhat_api
Product: Red Hat JBoss Enterprise Application Platform 7Fixed in: jena-core
redhatvendor investigatingvia redhat_api
Product: Red Hat JBoss Enterprise Application Platform 7Fixed in: jena-dboe-base
redhatvendor investigatingvia redhat_api
Product: Red Hat JBoss Enterprise Application Platform 7Fixed in: jena-dboe-index
redhatvendor investigatingvia redhat_api
Product: Red Hat JBoss Enterprise Application Platform 7Fixed in: jena-dboe-transaction
redhatvendor investigatingvia redhat_api
Product: Red Hat JBoss Enterprise Application Platform 7Fixed in: jena-dboe-trans-data
redhatvendor investigatingvia redhat_api
Product: Red Hat JBoss Enterprise Application Platform 7Fixed in: jena-iri
redhatvendor investigatingvia redhat_api
Product: Red Hat JBoss Enterprise Application Platform 7Fixed in: jena-rdfconnection
redhatvendor investigatingvia redhat_api
Product: Red Hat JBoss Enterprise Application Platform 7Fixed in: jena-shaded-guava
redhatvendor investigatingvia redhat_api
Product: Red Hat JBoss Enterprise Application Platform 7Fixed in: jena-tdb
redhatvendor investigatingvia redhat_api
Product: Red Hat JBoss Enterprise Application Platform 7Fixed in: jena-tdb2
redhatvendor investigatingvia redhat_api
Product: Red Hat JBoss Enterprise Application Platform 8Fixed in: jena-arq
redhatvendor investigatingvia redhat_api
Product: Red Hat JBoss Enterprise Application Platform 8Fixed in: jena-base
redhatvendor investigatingvia redhat_api
Product: Red Hat JBoss Enterprise Application Platform 8Fixed in: jena-core
redhatvendor investigatingvia redhat_api
Product: Red Hat JBoss Enterprise Application Platform 8Fixed in: jena-dboe-base
redhatvendor investigatingvia redhat_api
Product: Red Hat JBoss Enterprise Application Platform 8Fixed in: jena-dboe-index
redhatvendor investigatingvia redhat_api
Product: Red Hat JBoss Enterprise Application Platform 8Fixed in: jena-dboe-transaction
redhatvendor investigatingvia redhat_api
Product: Red Hat JBoss Enterprise Application Platform 8Fixed in: jena-dboe-trans-data
redhatvendor investigatingvia redhat_api
Product: Red Hat JBoss Enterprise Application Platform 8Fixed in: jena-iri
redhatvendor investigatingvia redhat_api
Product: Red Hat JBoss Enterprise Application Platform 8Fixed in: jena-rdfconnection
redhatvendor investigatingvia redhat_api
Product: Red Hat JBoss Enterprise Application Platform 8Fixed in: jena-shaded-guava
redhatvendor investigatingvia redhat_api
Product: Red Hat JBoss Enterprise Application Platform 8Fixed in: jena-tdb
redhatvendor investigatingvia redhat_api
Product: Red Hat JBoss Enterprise Application Platform 8Fixed in: jena-tdb2
redhatvendor investigatingvia redhat_api
Product: Red Hat JBoss Enterprise Application Platform Expansion PackFixed in: jena-arq
redhatvendor investigatingvia redhat_api
Product: Red Hat JBoss Enterprise Application Platform Expansion PackFixed in: jena-base
redhatvendor investigatingvia redhat_api
Product: Red Hat JBoss Enterprise Application Platform Expansion PackFixed in: jena-core
redhatvendor investigatingvia redhat_api
Product: Red Hat JBoss Enterprise Application Platform Expansion PackFixed in: jena-dboe-base
redhatvendor investigatingvia redhat_api
Product: Red Hat JBoss Enterprise Application Platform Expansion PackFixed in: jena-dboe-index
redhatvendor investigatingvia redhat_api
Product: Red Hat JBoss Enterprise Application Platform Expansion PackFixed in: jena-dboe-transaction
redhatvendor investigatingvia redhat_api
Product: Red Hat JBoss Enterprise Application Platform Expansion PackFixed in: jena-dboe-trans-data
redhatvendor investigatingvia redhat_api
Product: Red Hat JBoss Enterprise Application Platform Expansion PackFixed in: jena-iri
redhatvendor investigatingvia redhat_api
Product: Red Hat JBoss Enterprise Application Platform Expansion PackFixed in: jena-rdfconnection
redhatvendor investigatingvia redhat_api
Product: Red Hat JBoss Enterprise Application Platform Expansion PackFixed in: jena-shaded-guava
redhatvendor investigatingvia redhat_api
Product: Red Hat JBoss Enterprise Application Platform Expansion PackFixed in: jena-tdb
redhatvendor investigatingvia redhat_api
Product: Red Hat JBoss Enterprise Application Platform Expansion PackFixed in: jena-tdb2
redhatvendor investigatingvia redhat_api
Product: streams for Apache Kafka 2Fixed in: jena-base
redhatvendor investigatingvia redhat_api
Product: streams for Apache Kafka 2Fixed in: jena-core
redhatvendor investigatingvia redhat_api
Product: streams for Apache Kafka 2Fixed in: jena-iri
redhatvendor investigatingvia redhat_api
Product: streams for Apache Kafka 2Fixed in: jena-shaded-guava

Vendor Advisories (2)

mavenGHSA-xg9p-p463-3qjphigh

Apache Jena doesn't validate file access paths in configuration files uploaded by users with administrator access

Jul 21, 2025
redhatCVE-2025-50151Moderate

org.apache.jena: Apache Jena insufficent file validation

Jul 21, 2025

References

openwall.com / lists/oss-security/2025/07/21/2
lists.apache.org / thread/12gks5z40gh9bszn1xk8mz34gz586xss
Issue TrackingVendor Advisory