CVE Explorer
CVE-2025-9571
A remote code execution (RCE) vulnerability exists in Google Cloud Data Fusion.
A user with permissions to upload artifacts to a Data Fusion instance can execute arbitrary code within the core AppFabric component.
This could allow the attacker to gain control over the Data Fusion instance, potentially leading to unauthorized access to sensitive data, modification of data pipelines, and exploration of the underlying infrastructure.
The following CDAP versions include the necessary update to pro
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"defaultStatus":"unaffected","product":"Cloud Data Fusion","vendor":"Google Cloud","versions":[{"lessThan":"6.10.6","status":"affected","version":"0","versionType":"custom"},{"lessThan":"6.11.1","status":"affected","version":"0","versionType":"custom"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:6370d0672e21653da7e9479e0e83a61c99a1ce9e739dbf77373926b30e6363c8 · sha256:1aaf81ca495468c6… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","Safety":"NOT_DEFINED","attackComplexity":"LOW","attackRequirements":"NONE","attackVector":"NETWORK","baseScore":8.7,"baseSeverity":"HIGH","exploitMaturity":"NOT_DEFINED","privilegesRequired":"LOW","providerUrgency":"RED","subAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","userInteraction":"NONE","valueDensity":"NOT_DEFINED","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/U:Red","version":"4.0","vulnAvailabilityImpact":"HIGH","vulnConfidentialityImpact":"HIG…
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:6370d0672e21653da7e9479e0e83a61c99a1ce9e739dbf77373926b30e6363c8 · sha256:1aaf81ca495468c6… · /containers/cna/metrics/0/cvssV4_0
CWE assertions
1 source assertion{"cweId":"CWE-502","description":"CWE-502 Deserialization of Untrusted Data","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:6370d0672e21653da7e9479e0e83a61c99a1ce9e739dbf77373926b30e6363c8 · sha256:1aaf81ca495468c6… · /containers/cna/problemTypes/0/descriptions/0
Source references
1 source assertion{"url":"https://docs.cloud.google.com/support/bulletins#gcp-2025-076"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:6370d0672e21653da7e9479e0e83a61c99a1ce9e739dbf77373926b30e6363c8 · sha256:1aaf81ca495468c6… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.