GHSA-cxvc-g8f2-4gmm · Severity: medium · Ecosystem: maven — Apache Jackrabbit: Core and JCR Commons are vulnerable to Deserialization of Untrusted Data
Deserialization of Untrusted Data vulnerability in Apache Jackrabbit Core and Apache Jackrabbit JCR Commons. This issue affects Apache Jackrabbit Core: from 1.0.0 through 2.22.1; Apache Jackrabbit JCR Commons: from 1.0.0 through 2.22.1. Deployments that accept JNDI URIs for JCR lookup from untrusted users allows them to inject malicious JNDI references, potentially leading to arbitrary code execution through deserialization of untrusted data. Users are recommended to upgrade to version 2.22.2. JCR lookup through JNDI has been disabled by default in 2.22.2. Users of this feature need to enable it explicitly and are adviced to review their use of JNDI URI for JCR lookup.
Conclusion & alert: CVE-2025-58782 is rated Moderate Risk (50.4/100): CVSS Medium severity, with medium exploitation likelihood (EPSS 0.59%). Mandatory action: Review affected assets and schedule remediation.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-05-14 | 0.52% | 0.59% | +0.07% |
| 2 | 2026-02-16 | 0.40% | 0.52% | +0.12% |
| 3 | 2026-02-14 | — | 0.40% | — |
Full EPSS history (9 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 6.5 | 3.1 | MEDIUM |
|
3.9 | 2.5 | 134c704f-9b21-4f2e-91b3-4a467353bcc0 |
GHSA-cxvc-g8f2-4gmm · Severity: medium · Ecosystem: maven — Apache Jackrabbit: Core and JCR Commons are vulnerable to Deserialization of Untrusted Data
| vendor | priority | summary | link |
|---|---|---|---|
debian
|
not yet assigned | CVE-2025-58782 not yet assigned priority: Debian including 1 source packages (jackrabbit), 5 status rows across 5 suites (bookworm, bullseye, forky, sid, trixie): open 5. | https://security-tracker.debian.org/tracker/CVE-2025-58782 |
redhat
|
high | — | https://access.redhat.com/security/cve/CVE-2025-58782 |
ubuntu
|
medium | CVE-2025-58782 medium priority: Ubuntu including 1 source packages (jackrabbit), 9 status rows across 9 suites (bionic, focal, jammy, noble, plucky, questing, trusty, upstream, xenial): needs-triage 8, ignored 1. | https://ubuntu.com/security/CVE-2025-58782 |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| apache | jackrabbit | >= 1.0.0, < 2.22.2 | cpe:2.3:a:apache:jackrabbit:*:*:*:*:*:*:*:* |
| URL | Tags |
|---|---|
| https://lists.apache.org/thread/t4wdrost6dh17dh406g792j9wq6xmy6v | Mailing List Vendor Advisory |
| http://www.openwall.com/lists/oss-security/2025/09/06/3 | Mailing List Third Party Advisory |