Back to Vulnerability Directory
HIGHNot covered

CVE-2025-62228

Apache Flink CDC: SQL injection through crafted database or table names

Technology

Apache Flink CDC

CVSS Score

8.8 / 10.0

Affected Versions

Apache Flink CDC 3.0.0 to 3.4.0

Upstream Fix

Flink CDC 3.5.0

Published

October 9, 2025

OSSeva Coverage

Not covered

Description

Flink CDC is open to SQL injection through maliciously crafted identifiers such as a database or table name. Only a logged-in database user can trigger it. Apache, as the CNA, scores it 5.1 under CVSS 4.0; the score here is NVD's CVSS 3.1 score.

Upstream record: NVD · CVE.org

Is your Apache Flink CDC deployment affected?

If you're running Apache Flink CDC 3.0.0 to 3.4.0, you need this patch. Book a discovery call to get covered.