Encoding Error Affecting org.apache.linkis:linkis-common package, versions [1.3.0,]


Severity

Recommended
0.0
medium
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.76% (53rd percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-JAVA-ORGAPACHELINKIS-15035881
  • published19 Jan 2026
  • disclosed19 Jan 2026
  • creditLe1a, A1kaid

Introduced: 19 Jan 2026

CVE-2025-29847  (opens in a new tab)
CWE-172  (opens in a new tab)

How to fix?

A fix was pushed into the master branch but not yet published.

Overview

org.apache.linkis:linkis-common is a module that builds a computation middleware layer to facilitate connection, governance and orchestration between the upper applications and the underlying data engines.

Affected versions of this package are vulnerable to Encoding Error via the handling of JDBC parameters when multiple rounds of URL encoding are applied. An attacker can access arbitrary system files by submitting specially crafted requests that bypass input validation through double URL encoding.

CVSS Base Scores

version 4.0
version 3.1