Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 05 Feb 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Kutangguo
Kutangguo ktg-mes |
|
| CPEs | cpe:2.3:a:kutangguo:ktg-mes:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Kutangguo
Kutangguo ktg-mes |
Wed, 12 Nov 2025 23:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Alibaba
Alibaba fastjson |
|
| Vendors & Products |
Alibaba
Alibaba fastjson |
Wed, 12 Nov 2025 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-502 | |
| Metrics |
cvssV3_1
|
Mon, 10 Nov 2025 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | ktg-mes before commit a484f96 (2025-07-03) has a fastjson deserialization vulnerability. This is because it uses a vulnerable version of fastjson and deserializes unsafe input data. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-11-12T20:31:58.917Z
Reserved: 2025-10-27T00:00:00.000Z
Link: CVE-2025-63617
Updated: 2025-11-12T20:31:52.741Z
Status : Analyzed
Published: 2025-11-10T21:15:39.743
Modified: 2026-02-05T15:10:47.600
Link: CVE-2025-63617
No data.
OpenCVE Enrichment
Updated: 2025-11-12T22:16:13Z