CVE-2025-55017General

LOWCVSS 9.1 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache IoTDB. This issue affects Apache IoTDB: from 2.0.0 before 2.0.6, from 1.0.0 before 1.3.6. Users are recommended to upgrade to version 1.3.6 and 2.0.6, which fixes the issue.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-22

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • General: 2 classified signals
  • Peaked 1d ago at 2 mentions (2026-03-09); latest day: 1
  • 3 total mentions across 2 days

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-03-09: 2Mentions · 2026-06-28: 1Patch / Workaround · 2026-06-28: 1Technical Details · 2026-03-09: 1Technical Details · 2026-06-28: 103-0906-28
Signal classification2 categories
General
266.7%
Patch
133.3%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-03-092
General2
2026-06-281
Patch1
Full discourse3 posts
  • Open Source Security mailing list@oss_security
    General

    CVE-2025-55017: Apache IoTDB: Path Traversal https://www.openwall.com/lists/oss-security/2026/03/09/2 CVE-2025-64152: Apache IoTDB: Path Traversal https://www.openwall.com/lists/oss-security/2026/03/09/3 Two notifications of vulnerabilities (non-)described in the exact same way, but with slightly different affected and fixed version ranges

    Post summary

    Two separate path traversal vulnerabilities in Apache IoTDB are announced with similar descriptions but slight differences in affected and fixed version ranges.

    20052559
    4.4K followersView on X
  • Sami Laiho@samilaiho
    Patch

    Apache IoTDB: Path Traversal Vulnerability URL: https://nvd.nist.gov/vuln/detail/CVE-2025-55017 Classification: Critical, Solution: Official Fix, Exploit Maturity: Not Defined, CVSSv3.1: 9.1

    Post summary

    Apache IoTDB Path Traversal vulnerability CVE‑2025‑55017 is a critical issue with an official fix available; no PoC, exploit, or active exploitation is reported.

    00020676
    30.6K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2025-55017 CVE-2025-55017 https://vulmon.com/vulnerabilitydetails?qid=CVE-2025-55017

    Post summary

    The text merely references the CVE-2025-55017 identifier and a link to a vulnerability details page, without further technical or actionable information.

    0001080
    4.0K followersView on X

Explore more