← Advisories

Apache Ratis 3.3.1 Java Deserialization

High
Advisory ID
ZSL-2026-6010
Release Date
07 October 2026
Vendor
The Apache Software Foundation - https://www.apache.org
Affected Version
3.3.1 and 3.3.0
CVE
N/A
Tested On
Microsoft Windows 10 (x86_64), Eclipse Temurin OpenJDK 21.0.6 (LTS), SLF4J 1.7.36
Summary

Apache Ratis is a highly customizable Raft protocol implementation in Java. Raft is a easily understandable consensus algorithm to manage replicated state. Apache Ratis could be used in any Java application where state should be replicated between multiple instances.

Description

Apache Ratis suffers from an unsafe Java deserialization vulnerability in its RPC error handling. The cause and stack-trace bytes carried in an RPC reply exception are deserialized through IOUtils.readObject with no class filtering, so a malicious server (or a man-in-the-middle) can return a crafted exception whose bytes are deserialized in the receiving client. A gadget chain was run through the real IOUtils.readObject in ratis-3.3.1. This can result in remote code execution against a Ratis client where a suitable gadget is present on the client classpath. The trust precondition is a compromised/malicious server or MITM, so a peer-trust rebuttal is likely.

Proof of Concept
Disclosure Timeline
13.08.2026Vulnerability discovered.
18.08.2026Contact with the vendor.
19.08.2026Vendor forwards details to appropriate PMC.
06.10.2026No response from the vendor.
07.10.2026Public security advisory released.
Credits
Vulnerability discovered by Gjoko Krstic
References
Changelog
07.10.2026Initial release