logo

Critical Apache bRPC Framework Vulnerability Let Attackers Crash the Server

ID: 93ef4418-777a-5e8e-8160-d663667196b6

STIX ID: report--93ef4418-777a-5e8e-8160-d663667196b6

Feed Name: cybersecurityNews.com

Threat Score
75/100

Date Published: 2025-12-01

Date Updated: 2026-04-21

Author: Abinaya

...
...

A critical vulnerability (CVE-2025-59789, CVSS 9.8) in Apache bRPC's json2pb component allows remote attackers to crash servers by sending deeply nested JSON that triggers a stack overflow in the rapidjson recursive parser, causing denial-of-service; Apache fixed the issue in bRPC 1.15.0 and provided a patch that enforces a configurable recursion depth limit (default 100).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.