Apache Ignite
5 CVEs tracked. None of them is in CISA KEV.
This hub aggregates every CVE we track for Apache Ignite, a product in the databases space. Use it to gauge the current risk picture and drill into individual advisories.
Apache Ignite CVEs per month
| Month | CVEs |
|---|---|
| 2024-10 | 0 |
| 2024-11 | 0 |
| 2024-12 | 0 |
| 2025-01 | 0 |
| 2025-02 | 1 |
| 2025-03 | 0 |
| 2025-04 | 0 |
| 2025-05 | 0 |
| 2025-06 | 0 |
| 2025-07 | 0 |
| 2025-08 | 0 |
| 2025-09 | 0 |
| 2025-10 | 0 |
| 2025-11 | 0 |
| 2025-12 | 0 |
| 2026-01 | 0 |
| 2026-02 | 0 |
| 2026-03 | 0 |
| 2026-04 | 0 |
| 2026-05 | 1 |
| 2026-06 | 0 |
| 2026-07 | 0 |
| 2026-08 | 0 |
| 2026-09 | 0 |
Severity
How the 5 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.
- Critical3
- High1
- Medium1
Latest CVEs
The 5 most recently published vulnerabilities affecting Apache Ignite.
- CVE-2025-48977Apache Ignite: REST HTTP arbitrary file read vulnerability6.5
- CVE-2024-52577Apache Ignite: Possible RCE when deserializing incoming messages by the server node9.0
- CVE-2018-8018In Apache Ignite before 2.4.8 and 2.5.x before 2.5.3, the serialization mechanism does not have a list of classes allowed for serialization/deserialization, which makes it possible to run arbitrary...9.8
- CVE-2018-1295In Apache Ignite 2.3 or earlier, the serialization mechanism does not have a list of classes allowed for serialization/deserialization, which makes it possible to run arbitrary code when 3-rd party...9.8
- CVE-2017-7686Apache Ignite 1.0.0-RC3 to 2.0 uses an update notifier component to update the users about new project releases that include additional functionality, bug fixes and performance improvements. To do ...7.5
Product grouping is registry-driven, with AI assist and human review. How it works