CVE-2025-54472
Homebrew vulnerability analysis and mitigation

Overview

CVE-2025-54472 is a critical vulnerability discovered in Apache bRPC's Redis protocol parser affecting all versions prior to 1.14.1. The vulnerability was disclosed on August 14, 2025, and impacts Apache bRPC, an Industrial-grade RPC framework used in high-performance systems such as Search, Storage, Machine learning, Advertisement, and Recommendation systems (Security Online, NVD).

Technical details

The vulnerability stems from unlimited memory allocation in the Redis protocol parser. The root cause lies in how the bRPC Redis parser allocates memory for arrays and strings based on integer values read from incoming network data. If the integer read from the network is too large, it can trigger a bad alloc error leading to program crashes. While version 1.14.0 attempted to fix this by limiting memory allocation size, the limitation checking code was improperly implemented, potentially causing integer overflow and bypassing the limitation (NVD).

Impact

The vulnerability allows attackers to crash affected services remotely through a Denial-of-Service (DoS) condition. This impacts systems using bRPC either as a Redis Server providing network services to untrusted clients or as a Redis Client interacting with untrusted Redis services. The vulnerability has received a CVSS v3.1 base score of 7.5 (HIGH) from CISA-ADP (NVD, Security Online).

Mitigation and workarounds

Two mitigation approaches are recommended: 1) Upgrade to bRPC version 1.14.1, which contains the official fix, or 2) Apply the official patch from GitHub Pull Request #3050 manually. The patch introduces a default maximum allocation size of 64 MB for Redis parser operations. For systems requiring larger allocations, the limit can be adjusted using the gflag redismaxallocation_size parameter (NVD).

Additional resources


SourceThis report was generated using AI

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management