logo

CVE-2025-60021: Apache bRPC Flaw Opens Door to Remote Command Injection

ID: 22f70772-47f5-594f-a1dd-975a6ccee242

STIX ID: report--22f70772-47f5-594f-a1dd-975a6ccee242

Feed Name: securityonline.info

Threat Score
70/100

Date Published: 2026-01-17

Date Updated: 2026-04-23

Author: Ddos

...
...

Apache has released a security fix for CVE-2025-60021, an important command-injection vulnerability in the bRPC C++ RPC framework’s heap profiler (the /pprof/heap endpoint). The flaw allows attackers to inject and execute commands via the unvalidated extra_options parameter, affecting bRPC versions 1.11.0 up to but not including 1.15.0; administrators are advised to upgrade to 1.15.0 or apply the referenced GitHub patch (PR #3101) immediately to mitigate remote code execution risk.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.