GHSA-q37j-3367-fwv7
HIGHCVE-2025-26866A remote code execution vulnerability exists where a malicious Raft node can exploit insecure Hessian deserialization within the PD store. The fix enforces IP-based authentication to restrict cluster membership and implements a strict class whitelist to harden the Hessian serialization process against object injection attacks.
- Affected
- < 1.7.0
- Fixed in
- 1.7.0
- Weakness
- CWE-502
- Published
- 2025-12-12
- Source
- github