GHSA-7c3f-cg9x-f3gr · Severity: high · Ecosystem: maven — JasperReports has a Java deserialisation vulnerability
A Java deserialisation vulnerability has been discovered in Jaspersoft Library. Improper handling of externally supplied data may allow attackers to execute arbitrary code remotely on systems that use the affected library
Conclusion & alert: CVE-2025-10492 is rated Moderate Risk (60/100): CVSS High severity, with medium exploitation likelihood (EPSS 0.66%). Mandatory action: Review affected assets and schedule remediation.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-06-02 | 0.43% | 0.66% | +0.23% |
| 2 | 2026-05-22 | 0.52% | 0.43% | -0.09% |
| 3 | 2026-04-22 | — | 0.52% | — |
Full EPSS history (11 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 8.7 | 4.0 | HIGH |
|
— | — | db6d2600-d19b-4111-a010-f3c4ed70cd50 |
| 9.8 | 3.1 | CRITICAL |
|
3.9 | 5.9 | [email protected] |
GHSA-7c3f-cg9x-f3gr · Severity: high · Ecosystem: maven — JasperReports has a Java deserialisation vulnerability
| vendor | priority | summary | link |
|---|---|---|---|
ubuntu
|
medium | CVE-2025-10492 medium priority: Ubuntu including 1 source packages (jasperreports), 7 status rows across 7 suites (bionic, jammy, noble, plucky, questing, upstream, xenial): DNE 4, needs-triage 3. | https://ubuntu.com/security/CVE-2025-10492 |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| cloud | jasperreports_io | <= 4.0.0 | cpe:2.3:a:cloud:jasperreports_io:*:*:*:*:at-scale:*:*:* |
| cloud | jasperreports_io | <= 4.0.0 | cpe:2.3:a:cloud:jasperreports_io:*:*:*:*:professional:*:*:* |
| cloud | jasperreports_library | <= 7.0.3 | cpe:2.3:a:cloud:jasperreports_library:*:*:*:*:community:*:*:* |
| cloud | jasperreports_library | <= 9.0.2 | cpe:2.3:a:cloud:jasperreports_library:*:*:*:*:professional:*:*:* |
| cloud | jasperreports_server | <= 9.0.0 | cpe:2.3:a:cloud:jasperreports_server:*:*:*:*:*:*:*:* |
| cloud | jasperreports_studio | <= 7.0.3 | cpe:2.3:a:cloud:jasperreports_studio:*:*:*:*:community:*:*:* |
| cloud | jasperreports_studio | <= 9.0.2 | cpe:2.3:a:cloud:jasperreports_studio:*:*:*:*:professional:*:*:* |
| cloud | jasperreports_web_studio | <= 3.0.1 | cpe:2.3:a:cloud:jasperreports_web_studio:*:*:*:*:*:*:*:* |