Uncontrolled Recursion Vulnerability in Apache bRPC Affects Remote Servers
CVE-2025-59789
What is CVE-2025-59789?
An uncontrolled recursion vulnerability exists in the json2pb component of Apache bRPC prior to version 1.15.0. This flaw allows remote attackers to exploit the server by sending deeply recursive JSON data, potentially causing a stack overflow that leads to server crashes. The root of the issue lies in the default recursive parsing behavior of the rapidjson library used by bRPC for network data parsing. To mitigate this vulnerability, users should upgrade to bRPC version 1.15.0 or apply a specific patch, keeping in mind that a recursion depth limit is now enforced by default.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Apache bRPC 0 < 1.15.0
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved