CVE-2025-60021 | Apache bRPC up to 1.14.x Hheap Profiler Builtin Service /pprof/heap extra_options command injection
A vulnerability marked as critical has been reported in Apache bRPC up to 1.14.x. Impacted is an unknown function of the file /pprof/heap of the component Hheap Profiler Builtin Service. The manipulation of the argument extra_options leads to command injection.
This vulnerability is referenced as CVE-2025-60021. Remote exploitation of the attack is possible. No exploit is available.
It is suggested to upgrade the affected component.