
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-24404 is an XML Injection Remote Code Execution (RCE) vulnerability in Apache HertzBeat (incubating), an open-source real-time monitoring platform. The vulnerability exists in the HTTP sitemap XML response parsing functionality, allowing an authenticated attacker to trigger XML parsing flaws by adding a specially crafted monitor. It affects all versions of Apache HertzBeat (incubating) before 1.7.0, and was publicly disclosed on September 5–9, 2025, with credit to researchers unam4, springkill, and Zoiltin (OSS-Security, Apache Mailing List). The vulnerability carries a CVSS v3.1 base score of 8.8 (High) (Red Hat).
The root cause is classified as CWE-91 (XML Injection / Blind XPath Injection), arising from insufficient sanitization of XML content returned by monitored HTTP sitemap endpoints. An authenticated attacker with low privileges can configure a new monitor in HertzBeat that points to an attacker-controlled HTTP endpoint; when HertzBeat fetches and parses the XML sitemap response, the malicious XML payload triggers the injection vulnerability, ultimately leading to remote code execution on the server. No user interaction beyond the initial monitor configuration is required, and the attack is conducted entirely over the network (OSS-Security, Red Hat).
Successful exploitation grants an attacker with a low-privileged authenticated account the ability to execute arbitrary code on the HertzBeat server, resulting in full compromise of confidentiality, integrity, and availability. This could allow exfiltration of sensitive monitoring credentials and configuration data, modification or destruction of monitoring data, and disruption of the HertzBeat service. Given HertzBeat's role as a centralized monitoring platform, a compromised instance may also expose credentials or network topology information for all monitored systems, creating significant lateral movement risk (Red Hat, OSS-Security).
bash, sh, curl, wget, python); unusual network connections initiated by the HertzBeat service account.The Apache Software Foundation has released version 1.7.0 of Apache HertzBeat (incubating), which resolves this vulnerability. All users running versions prior to 1.7.0 should upgrade immediately (OSS-Security, Apache Mailing List). As interim mitigations, administrators should restrict authenticated access to trusted users only, audit existing monitor configurations for suspicious external URLs, implement network egress controls to limit outbound connections from the HertzBeat server, and enforce strict XML parsing controls with input validation for monitor-sourced content.
The vulnerability was discussed briefly on the oss-security mailing list following the coordinated disclosure by the Apache Security Team (OSS-Security). A technical write-up was published on Medium/Plain English covering the XML injection attack vector and its RCE implications. Social media activity was limited, with some mentions on Bluesky and security aggregator platforms such as VulDB and Vulners. Overall community reaction has been measured, reflecting the authenticated-only exploitation requirement that reduces the immediate urgency compared to unauthenticated RCE vulnerabilities.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."