Apache Security Update Advisory (CVE-2025-59789)

Apache Security Update Advisory (CVE-2025-59789)

Overview

We have released security updates to fix vulnerabilities in Apache products. Users of affected products are advised to update to the latest version.

 

Affected Products

CVE-2025-59789

 

Apache bRPC version: 1.15.0 or earlier

 

Resolved Vulnerabilities

 

Stack overflow vulnerability due to unbounded recursion in the JSON parser in Apache bRPC (CVE-2025-59789)

Vulnerability Patches

Vulnerability patches have been made available in the latest updates. Please follow the instructions on the Referenced Sites to update to the latest Vulnerability Patches version.

CVE-2025-59789

 

Apache bRPC Version: 1.15.0

 

Referenced Sites

[1] CVE-2025-59789: Apache bRPC: Stack Exhaustion via Unbounded
https://www.openwall.com/lists/oss-security/2025/12/01/1