
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-62233 is a Deserialization of Untrusted Data vulnerability in the RPC module of Apache DolphinScheduler, a distributed workflow scheduling platform. It affects versions 3.2.0 through 3.3.0 (i.e., >= 3.2.0 and < 3.3.1), specifically the org.apache.dolphinscheduler:dolphinscheduler-rpc and org.apache.dolphinscheduler:dolphinscheduler-extract-base Maven packages. The vulnerability was disclosed on April 24, 2026, via the Apache security mailing list and the GitHub Advisory Database. It carries a CVSS v3.1 base score of 6.3 (Medium/Moderate) (GitHub Advisory, oss-security).
The root cause is improper deserialization of untrusted data (CWE-502) within the DolphinScheduler RPC module. An attacker with network access to Master or Worker nodes can craft a malicious StandardRpcRequest object, injecting an arbitrary class type into it, and transmit it via the RPC interface. Because the server deserializes the incoming request without sufficient validation of the class type, the injected payload is instantiated, potentially triggering gadget chains that lead to remote code execution. Exploitation requires low-level privileges (network access to the internal RPC port) but no user interaction (GitHub Advisory, oss-security).
Successful exploitation can result in remote code execution on affected Master or Worker nodes, with low-to-moderate impact on confidentiality, integrity, and availability of the DolphinScheduler system. An attacker who compromises a Master or Worker node could disrupt scheduled workflows, access sensitive job configurations or credentials stored within the scheduler, and potentially pivot to other systems reachable from the compromised node. The scope is limited to the affected component (unchanged scope), but the centralized nature of DolphinScheduler's Master node makes it a high-value target (GitHub Advisory, Feedly).
There is no public proof-of-concept exploit or evidence of active in-the-wild exploitation as of the time of disclosure (Feedly). The EPSS score is approximately 0.024% (0.000240), placing it in the 19th percentile for exploitation probability within 30 days. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires an attacker to have network-level access to the internal RPC ports of Master or Worker nodes, which limits the attack surface to environments where these ports are exposed to untrusted networks (GitHub Advisory).
StandardRpcRequest object with a malicious class type injected into the class type field. Select a Java deserialization gadget chain compatible with libraries present on the DolphinScheduler classpath./bin/bash, cmd.exe, curl, wget, python); unexpected network connections initiated by the JVM process.The primary remediation is to upgrade Apache DolphinScheduler to version 3.3.1 or later, which contains the fix for this vulnerability (GitHub Advisory, oss-security). If immediate patching is not feasible, implement strict network-level access controls (firewall rules, network segmentation) to restrict access to Master and Worker RPC ports to only trusted internal hosts. Additionally, monitor RPC traffic for anomalous serialized payloads or unexpected class types as a detection measure until patching can be completed (Feedly).
The vulnerability was reported by security researchers identified as 75Acol, fcgboy, ch0wn, and zer0duck, and was disclosed by Apache committer Wenjun Ruan via the oss-security mailing list on April 24, 2026 (oss-security). A brief mention appeared on Bluesky shortly after disclosure, and the vulnerability was catalogued by several vulnerability tracking services including VulDB and CIRCL. No significant vendor statements beyond the official Apache advisory or notable media coverage have been identified.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."