Known vulnerabilities in Apache bRPC
Vendor:
Apache Foundation
Software:
Apache bRPC
Software CPE:
cpe:2.3:a:apache_foundation:brpc:*:*:*:*:*:*:*:*
Website:
https://www.apache.org
Total vulnerabilities:
5
Public exploits:
1
Known exploited (KEV):
0
Highest CVSSv4 Score:
8.8
Breakdown by Severity Chart
Vulnerabilities (5)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU121614 - Argument Injection or Modification CVE-2025-60021 |
CWE-88 | Medium | 1.15.0 | 16.01.2026 |
SB2025120446 |
||
| #VU119156 - Uncontrolled Recursion CVE-2025-59789 |
CWE-674 | Medium | 1.15.0 | 04.12.2025 |
SB2025120446 |
||
| #VU86311 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') CVE-2024-23452 |
CWE-444 | Medium | 1.8.0 | 09.02.2024 |
SB2024020946 |
||
| #VU86310 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') CVE-2023-45757 |
CWE-79 | Low | 1.6.1 | 09.02.2024 |
SB2024020945 |
||
| #VU76046 - Permissions, Privileges, and Access Controls CVE-2023-31039 |
CWE-264 | Low | 1.5.0 | 11.05.2023 |
SB2023051141 |