XML Injection Vulnerability in Apache HertzBeat
CVE-2025-24404
Key Information:
- Vendor
Apache
- Vendor
- CVE Published:
- 9 September 2025
What is CVE-2025-24404?
An XML Injection vulnerability has been identified in Apache HertzBeat, specifically affecting versions prior to 1.7.0. This vulnerability allows an authorized attacker to exploit XML parsing processes within the application by injecting malicious content into the HTTP sitemap XML response. By successfully manipulating how the application processes XML, an attacker can potentially execute remote commands, leading to unauthorized access and control over the system. It is crucial for users to upgrade to version 1.7.0 to mitigate this risk and protect their environments.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Apache HertzBeat (incubating) 0 < 1.7.0
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved