CVE-2026-24343

CWE-6434 documents4 sources
Severity
8.8HIGH
EPSS
0.0%
top 94.00%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 10

Description

Improper Neutralization of Data within XPath Expressions ('XPath Injection') vulnerability in Apache HertzBeat. This issue affects Apache HertzBeat: from 1.7.1 before 1.8.0. Users are recommended to upgrade to version 1.8.0, which fixes the issue.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages2 packages

NVDapache/hertzbeat1.7.11.8.0

🔴Vulnerability Details

2
CVEList
Apache HertzBeat: Uncontrolled Resource Consumption via Crafted XPath Expressions2026-02-10
GHSA
GHSA-jr4c-vcm8-65vh: Improper Neutralization of Data within XPath Expressions ('XPath Injection') vulnerability in Apache HertzBeat2026-02-10

🕵️Threat Intelligence

1
Wiz
CVE-2026-24343 Impact, Exploitability, and Mitigation Steps | Wiz
CVE-2026-24343 (HIGH CVSS 8.8) | Improper Neutralization of Data wit | cvebase.io