SEPTEMBER 23, 2026
Live Feed
Back to database
Case File

CVE-2025-66335

MEDIUM · CVSS 5.3 EPSS 0.66%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2026-04-20 · Last synced 2026-08-04

CyberRota Analysis

This is a medium severity vulnerability with a CVSS score of 5.3. It affects Apache.

CVE
CVE-2025-66335
Severity
MEDIUM
CVSS
5.3
EPSS
0.66%
Apache

Original NVD Description

Apache Doris MCP Server versions earlier than 0.6.1 are affected by an improper neutralization flaw in query context handling that may allow execution of unintended SQL statements and bypass of intended query validation and access restrictions through the MCP query execution interface. Version 0.6.1 and later are not affected.

Related CVEs

Other vulnerabilities affecting the same vendor(s)