Critical Apache bRPC Framework Vulnerability Let Attackers Crash the Server
ID: 93ef4418-777a-5e8e-8160-d663667196b6
STIX ID: report--93ef4418-777a-5e8e-8160-d663667196b6
Feed Name: cybersecurityNews.com
Threat Score
A critical vulnerability (CVE-2025-59789, CVSS 9.8) in Apache bRPC's json2pb component allows remote attackers to crash servers by sending deeply nested JSON that triggers a stack overflow in the rapidjson recursive parser, causing denial-of-service; Apache fixed the issue in bRPC 1.15.0 and provided a patch that enforces a configurable recursion depth limit (default 100).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
