CVE-2025-24404
Apache HertzBeat vulnerability analysis and mitigation

Overview

CVE-2025-24404 is an XML Injection Remote Code Execution (RCE) vulnerability in Apache HertzBeat (incubating), an open-source real-time monitoring platform. The vulnerability exists in the HTTP sitemap XML response parsing functionality, allowing an authenticated attacker to trigger XML parsing flaws by adding a specially crafted monitor. It affects all versions of Apache HertzBeat (incubating) before 1.7.0, and was publicly disclosed on September 5–9, 2025, with credit to researchers unam4, springkill, and Zoiltin (OSS-Security, Apache Mailing List). The vulnerability carries a CVSS v3.1 base score of 8.8 (High) (Red Hat).

Technical details

The root cause is classified as CWE-91 (XML Injection / Blind XPath Injection), arising from insufficient sanitization of XML content returned by monitored HTTP sitemap endpoints. An authenticated attacker with low privileges can configure a new monitor in HertzBeat that points to an attacker-controlled HTTP endpoint; when HertzBeat fetches and parses the XML sitemap response, the malicious XML payload triggers the injection vulnerability, ultimately leading to remote code execution on the server. No user interaction beyond the initial monitor configuration is required, and the attack is conducted entirely over the network (OSS-Security, Red Hat).

Impact

Successful exploitation grants an attacker with a low-privileged authenticated account the ability to execute arbitrary code on the HertzBeat server, resulting in full compromise of confidentiality, integrity, and availability. This could allow exfiltration of sensitive monitoring credentials and configuration data, modification or destruction of monitoring data, and disruption of the HertzBeat service. Given HertzBeat's role as a centralized monitoring platform, a compromised instance may also expose credentials or network topology information for all monitored systems, creating significant lateral movement risk (Red Hat, OSS-Security).

Exploitation steps

  1. Obtain Authenticated Access: Acquire a low-privileged authenticated account on the target Apache HertzBeat instance (e.g., through credential theft, phishing, or use of default credentials).
  2. Set Up Malicious HTTP Server: Deploy an attacker-controlled HTTP server that serves a specially crafted XML sitemap response containing a malicious XML injection payload (e.g., an XXE payload or other XML injection construct designed to trigger code execution during parsing).
  3. Add Malicious Monitor: Log into HertzBeat and create a new HTTP sitemap monitor configured to point to the attacker-controlled server URL.
  4. Trigger XML Parsing: Wait for or manually trigger HertzBeat to fetch and parse the XML response from the attacker's server. The vulnerable XML parser processes the malicious content without adequate sanitization.
  5. Achieve RCE: The injected XML payload executes arbitrary code on the HertzBeat server in the context of the application process, enabling reverse shell establishment, data exfiltration, or further lateral movement (OSS-Security, Red Hat).

Indicators of compromise

  • Network: Outbound HTTP requests from the HertzBeat server to unexpected or external IP addresses/domains during monitor polling cycles; unusual DNS lookups originating from the HertzBeat process.
  • Logs: HertzBeat application logs showing errors or exceptions during XML sitemap parsing for newly added monitors; monitor configuration entries pointing to external or non-standard URLs.
  • Process: Unexpected child processes spawned by the HertzBeat Java process (e.g., bash, sh, curl, wget, python); unusual network connections initiated by the HertzBeat service account.
  • File System: New or modified files in the HertzBeat installation directory, including web shells, scripts, or unexpected binaries created by the application process.
  • Configuration: Newly created HTTP sitemap monitors with URLs pointing to external or attacker-controlled hosts, especially those added by low-privileged accounts.

Mitigation and workarounds

The Apache Software Foundation has released version 1.7.0 of Apache HertzBeat (incubating), which resolves this vulnerability. All users running versions prior to 1.7.0 should upgrade immediately (OSS-Security, Apache Mailing List). As interim mitigations, administrators should restrict authenticated access to trusted users only, audit existing monitor configurations for suspicious external URLs, implement network egress controls to limit outbound connections from the HertzBeat server, and enforce strict XML parsing controls with input validation for monitor-sourced content.

Community reactions

The vulnerability was discussed briefly on the oss-security mailing list following the coordinated disclosure by the Apache Security Team (OSS-Security). A technical write-up was published on Medium/Plain English covering the XML injection attack vector and its RCE implications. Social media activity was limited, with some mentions on Bluesky and security aggregator platforms such as VulDB and Vulners. Overall community reaction has been measured, reflecting the authenticated-only exploitation requirement that reduces the immediate urgency compared to unauthenticated RCE vulnerabilities.

Additional resources


SourceThis report was generated using AI

Related Apache HertzBeat vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-24343HIGH8.8
  • Apache HertzBeat logoApache HertzBeat
  • cpe:2.3:a:apache:hertzbeat
NoYesFeb 10, 2026
CVE-2025-48208HIGH8.8
  • Apache HertzBeat logoApache HertzBeat
  • cpe:2.3:a:apache:hertzbeat
NoYesSep 09, 2025
CVE-2025-24404HIGH8.8
  • Apache HertzBeat logoApache HertzBeat
  • cpe:2.3:a:apache:hertzbeat
NoYesSep 09, 2025
CVE-2024-45791HIGH7.5
  • Apache HertzBeat logoApache HertzBeat
  • cpe:2.3:a:apache:hertzbeat
NoYesNov 18, 2024
CVE-2024-56736MEDIUM6.5
  • Apache HertzBeat logoApache HertzBeat
  • cpe:2.3:a:apache:hertzbeat
NoYesApr 16, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management