Apache bRPC Vulnerability Enables Remote Command Injection
ID: f71f71a6-fc23-5908-85c0-f34e6aa9d634
STIX ID: report--f71f71a6-fc23-5908-85c0-f34e6aa9d634
Feed Name: cybersecurityNews.com
Threat Score
A critical unauthenticated remote command injection (CVE-2025-60021) in Apache bRPC's built-in heap profiler (/pprof/heap) affects versions prior to 1.15.0 by failing to sanitize the extra_options parameter for jemalloc memory profiling, enabling remote code execution; immediate remediation is advised by upgrading to 1.15.0 or applying the official patch (PR #3101).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
