logo

Apache bRPC Vulnerability Enables Remote Command Injection

ID: f71f71a6-fc23-5908-85c0-f34e6aa9d634

STIX ID: report--f71f71a6-fc23-5908-85c0-f34e6aa9d634

Feed Name: cybersecurityNews.com

Threat Score
75/100

Date Published: 2026-01-20

Date Updated: 2026-04-21

Author: Abinaya

...
...

A critical unauthenticated remote command injection (CVE-2025-60021) in Apache bRPC's built-in heap profiler (/pprof/heap) affects versions prior to 1.15.0 by failing to sanitize the extra_options parameter for jemalloc memory profiling, enabling remote code execution; immediate remediation is advised by upgrading to 1.15.0 or applying the official patch (PR #3101).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.