CVE-2025-49656: Apache Jena

High severity, CVSS 7.5. EPSS: 1.5% chance of exploitation in the next 30 days.

Users with administrator access can create databases files outside the files area of the Fuseki server. This issue affects Apache Jena version up to 5.4.0. Users are recommended to upgrade to version 5.5.0, which fixes the issue.

Affected products

  • Apache Jena: before 5.5.0 (fixed in 5.5.0)

Published 2025-07-21. Last modified 2026-06-17.