CVE-2025-62228: Apache Flink CDC, Apache Flink CDC, Apache Flink CDC, Apache Flink CDC, Apache Flink CDC: SQL injection via maliciously crafted identifiers
Apache Flink CDC version 3.0.0 to before 3.5.0 are vulnerable to a SQL injection via maliciously crafted identifiers eg. crafted database name or crafted table name. Even through only the logged-in database user can trigger the attack, users are recommended to update Flink CDC version to 3.5.0 which address this issue.
Other sources
Apache Flink CDC version 3.4.0 was vulnerable to a SQL injection via maliciously crafted identifiers eg. crafted database name or crafted table name. Even through only the logged-in database user can trigger the attack, we recommend users update Flink CDC version to 3.5.0 which address this issue.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-62228?
CVE-2025-62228 has been rated as a high-severity vulnerability due to its potential for SQL injection attacks.
How do I fix CVE-2025-62228?
To mitigate CVE-2025-62228, upgrade Apache Flink CDC to version 3.5.0 or later.
What software is affected by CVE-2025-62228?
CVE-2025-62228 affects Apache Flink CDC version 3.4.0.
What kind of attack does CVE-2025-62228 enable?
CVE-2025-62228 enables SQL injection attacks through maliciously crafted identifiers.
Who can trigger the CVE-2025-62228 vulnerability?
Only logged-in database users can trigger the CVE-2025-62228 vulnerability.