CVE-2025-48977
MediumAdvisory
Published 28 May 2026In the index since 8 Sept 2026
- Severity
- Medium
- worst across findings
- CVSS
- 6.5
- base score, highest
- EPSS
- 0.005
- 43rd percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 5
- of 17,781 indexed, latest versions
- Container images
- 5
- deployed by those charts
- Fix available
- 1 of 1
- affected package
Apache Ignite REST API Has a Relative Path Traversal Vulnerability
Carried by container images the latest versions of 5 of 17,781 indexed charts deploy, on 5 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| ignite-coremaven | 2.7.0, 2.16.0, 2.17.0 | 2.18.0 | 5 |
- OSV records
- GHSA-v45h-mqf4-6939
Charts affected
5 by stars
Container images carrying it
5 by charts deploying them
A fixed version is listed for 1 of the 1 affected package.
| Container image | Digest | Package | Fixed in | Used by |
|---|---|---|---|---|
| apacheignite/ | d7deab68b8fa | ignite-core | 2.18.0 | 1 |
| trinodb/ | 1565e8cac299 | ignite-core | 2.18.0 | 1 |
| trinodb/ | 38c6f24ab1a4 | ignite-core | 2.18.0 | 1 |
| trinodb/ | 5b5e0a97f599 | ignite-core | 2.18.0 | 1 |
| trinodb/ | 6af989b0846d | ignite-core | 2.18.0 | 1 |