CVE-2025-60021Disclosure(apache / brpc)

MEDIUMCVSS 9.8 · CRITICAL

Exploitation ongoing with high activity in latest observed window (2 mentions)

Immediate actions

  • Patch apache brpc systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

Remote command injection vulnerability in heap profiler builtin service in Apache bRPC ((all versions < 1.15.0)) on all platforms allows attacker to inject remote command. Root Cause: The bRPC heap profiler built-in service (/pprof/heap) does not validate the user-provided extra_options parameter and executes it as a command-line argument. Attackers can execute remote commands using the extra_options parameter.. Affected scenarios: Use the built-in bRPC heap profiler service to perform jemalloc memory profiling. How to Fix: we provide two methods, you can choose one of them: 1. Upgrade bRPC to version 1.15.0. 2. Apply this patch ( https://github.com/apache/brpc/pull/3101 ) manually.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-77

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • brpc

Threat summary

  • Active exploitation appears in 1 classified signals
  • Patch or workaround signal is available
  • 5 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 5 signals
  • Disclosure: 3 classified signals
  • General: 1 classified signal
  • Peaked 1d ago at 2 mentions (2026-02-02); latest day: 2
  • 5 total mentions across 3 days

Affected systems

Vendors
Products
brpc

Deep dive

Activity timeline5 mentions / 3d
01122Mentions · 2026-01-29: 1Mentions · 2026-02-02: 2Mentions · 2026-03-11: 2Active Exploitation · 2026-02-02: 1Patch / Workaround · 2026-02-02: 1Technical Details · 2026-01-29: 1Technical Details · 2026-02-02: 2Technical Details · 2026-03-11: 201-2902-0203-11
Signal classification3 categories
Disclosure
360.0%
Active Exploitation
120.0%
General
120.0%
Referenced assets3 URLs
By indicator
Classification over time
DateTotalLabels
2026-01-291
Disclosure1
2026-02-022
Active Exploitation1General1
2026-03-112
Disclosure2
Full discourse5 posts
  • transilienceai@transilienceai
    General

    @f3dscr0w While the query mentions a CVSS of 10.0, related sources note a similar Apache bRPC command injection flaw (also CVE-2025-60021) scored at 9.8, indicating high severity regardless. 📊 #Vulnerability

    Post summary

    The tweet highlights CVE-2025-60021 as a high‑severity command injection flaw in Apache bRPC but offers no evidence of exploitation or remediation.

    1000048
    317 followersView on X
  • _cr0w_@f3dscr0w
    Active Exploitation

    SmarterMail CVE-2025-60021 enables RCE via auth bypass. With CVSS 10.0, update vulnerable instances ASAP. Honeypots show active exploits. How do you prioritize patching email servers? #CVE #EmailSecurity

    Post summary

    CVE-2025-60021 in SmarterMail enables RCE through an authentication bypass with a CVSS of 10.0; active exploitation has been observed, urging immediate patching of affected email servers.

    1000083
    32 followersView on X
  • B2B Cyber Security.de@B2bCyber
    Disclosure

    https://ift.tt/KY1ItT9 Critical security vulnerability in Apache bRPC Security experts have identified a critical vulnerability (CVE-2025-60021, CVSS 9.8) in Apache bRPC, a widely used C++ framework for high-performance microservices. The vulnerability allows remote code exe… https://t.co/pLNiRUrzpE

    Post summary

    A new high‑severity vulnerability (CVE‑2025‑60021, CVSS 9.8) in Apache bRPC has been disclosed; no PoC, exploit code, or mitigation details are provided.

    00000104
    1.7K followersView on X
  • B2B Cyber Security.de@B2bCyber
    Disclosure

    Kritische Sicherheitslücke in Apache bRPC https://ift.tt/f0i4t21 Sicherheitsexperten haben eine kritische Sicherheitslücke (CVE-2025-60021, CVSS 9.8) in Apache bRPC identifiziert – einem weit verbreiteten C++-Framework für performante Microservices. Die Schwachstelle ermögli…

    Post summary

    A critical vulnerability (CVE‑2025‑60021) with a high CVSS score (9.8) was identified in the Apache bRPC framework, but no PoC, exploit code, or patch information is mentioned.

    00000109
    1.7K followersView on X
  • Arnav Sharma 🇦🇺@arnavsharma
    Disclosure

    Command injection in Apache bRPC heap profiler (CVE-2025-60021) A critical command injection flaw in Apache bRPC's /pprof/heap endpoint enables unauthenticated remote code execution (CVE-2025-60021, CVSS 9.8). https://ift.tt/DPnSOVh #CyberSecurity #AusCyber #ACSMag

    Post summary

    A critical command injection flaw is disclosed in Apache bRPC's /pprof/heap endpoint (CVE-2025-60021), enabling unauthenticated remote code execution with a CVSS score of 9.8.

    00000103
    2.3K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appapachebrpc---

Explore more