Apache HertzBeat: Uncontrolled Resource Consumption via Crafted XPath Expressions
No sign of exploitation. No public exploitation artifact known so far.
Apache HertzBeat contains a vulnerability where attackers can inject malicious XPath expressions to consume excessive server resources, potentially causing the application to become unresponsive or crash. This affects versions 1.7.1 through 1.8.0, and upgrading is strongly recommended.
XPath injection vulnerability in Apache HertzBeat (1.7.1 to <1.8.0) allows unauthenticated attackers to craft specially designed XPath expressions that trigger uncontrolled resource consumption, leading to denial of service. The vulnerability stems from improper neutralization of user-supplied input in XPath queries, enabling attackers to manipulate query execution and exhaust system resources.