Skip to content
dolphinschedulerGHSA-f786-9c63-8xr8

Apache DolphinScheduler RPC module has a Deserialization of Untrusted Data vulnerability

Medium6.3CVE-2025-62233 · Published Apr 24, 2026 · updated May 5, 2026

Deserialization of Untrusted Data vulnerability in Apache DolphinScheduler RPC module. This issue affects Apache DolphinScheduler:  Version >= 3.2.0 and < 3.3.1. Attackers who can access the Master or Worker nodes can compromise the system by creating a StandardRpcRequest, injecting a malicious class type into it, and sending RPC requests to the DolphinScheduler Master/Worker nodes. Users are recommended to upgrade to version [3.3.1], which fixes the issue.

GitHub advisory

Affected versions

PackageAffectedFixed in
org.apache.dolphinscheduler:dolphinscheduler
Maven
>= 3.2.0, < 3.3.13.3.1
Details and references
CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Severity from
GitHub (reviewed advisory)
Weakness
CWE-502
Also known as
CVE-2025-62233

More dolphinscheduler advisories

All dolphinscheduler

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.