Apache Security Update Advisory (CVE-2025-59789)
Overview
We have released security updates to fix vulnerabilities in Apache products. Users of affected products are advised to update to the latest version.
Affected Products
CVE-2025-59789
Apache bRPC version: 1.15.0 or earlier
Resolved Vulnerabilities
Stack overflow vulnerability due to unbounded recursion in the JSON parser in Apache bRPC (CVE-2025-59789)
Vulnerability Patches
Vulnerability patches have been made available in the latest updates. Please follow the instructions on the Referenced Sites to update to the latest Vulnerability Patches version.
CVE-2025-59789
Apache bRPC Version: 1.15.0
Referenced Sites
[1] CVE-2025-59789: Apache bRPC: Stack Exhaustion via Unbounded
https://www.openwall.com/lists/oss-security/2025/12/01/1