CVE-2025-53602: Open Zipkin Zipkin

Medium severity, CVSS 5.3. EPSS: 0.3% chance of exploitation in the next 30 days.

Zipkin through 3.5.1 has a /heapdump endpoint (associated with the use of Spring Boot Actuator), a similar issue to CVE-2025-48927.

Affected products

Published 2025-07-04. Last modified 2026-06-17.