CVE-2025-59060Disclosure(apache / ranger)

LOWCVSS 5.3 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch apache ranger systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Hostname verification bypass issue in Apache Ranger NiFiRegistryClient is reported in Apache Ranger versions <= 2.7.0. Users are recommended to upgrade to version 2.8.0, which fixes this issue.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-297

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • ranger

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • Peaked 1d ago at 3 mentions (2026-03-03); latest day: 1
  • 4 total mentions across 2 days

Affected systems

Vendors
Products
ranger

Deep dive

Activity timeline4 mentions / 2d
01223Mentions · 2026-03-03: 3Mentions · 2026-03-08: 1Patch / Workaround · 2026-03-03: 2Technical Details · 2026-03-03: 2Technical Details · 2026-03-08: 103-0303-08
Signal classification3 categories
Disclosure
250.0%
General
125.0%
Patch
125.0%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-03-033
Disclosure1General1Patch1
2026-03-081
Disclosure1
Full discourse4 posts
  • Open Source Security mailing list@oss_security
    Disclosure

    CVE-2025-59060: Apache Ranger: Hostname verification bypass in NiFiRegistryClient and NifiClient https://www.openwall.com/lists/oss-security/2026/03/02/4 CVE-2025-59059: Apache Ranger: Remote Code Execution Vulnerability in NashornScriptEngineCreator https://www.openwall.com/lists/oss-security/2026/03/02/5 Both are "Severity: low"

    Post summary

    An email list post discloses two low‑severity Apache Ranger CVEs: a hostname‑verification bypass in the NiFiRegistryClient and NifiClient, and a remote code execution flaw in NashornScriptEngineCreator.

    00052632
    4.4K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2025-59060 Hostname verification bypass issue in Apache Ranger NiFiRegistryClient/NiFiClient is reported in Apache Ranger versions &lt;= 2.7.0. Users are recommended to upgrade to… https://www.cve.org/CVERecord?id=CVE-2025-59060 ----- Traducción: CVE-2025-59060 Pro… http://infoflow.cloud`

    Post summary

    A hostname verification bypass vulnerability (CVE-2025-59060) was disclosed for Apache Ranger versions <=2.7.0, with users advised to upgrade to mitigate the issue.

    0000076
    55 followersView on X
  • CVE@CVEnew
    Patch

    CVE-2025-59060 Hostname verification bypass issue in Apache Ranger NiFiRegistryClient/NiFiClient is reported in Apache Ranger versions &lt;= 2.7.0. Users are recommended to upgrade to… https://www.cve.org/CVERecord?id=CVE-2025-59060

    Post summary

    CVE-2025-59060 is a hostname verification bypass affecting Apache Ranger versions up to 2.7.0, and users are advised to upgrade to remediate the vulnerability.

    00000362
    56.6K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2025-59060 CVE-2025-59060 https://vulmon.com/vulnerabilitydetails?qid=CVE-2025-59060

    Post summary

    The text only lists the CVE ID and a link to a vulnerability details page, with no additional information.

    0000076
    4.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appapacheranger---

Explore more