Apache HertzBeat XPath Injection Vulnerability

Vulnerability

A vulnerability allowing XPath injection has been identified in Apache HertzBeat versions 1.7.1 prior to 1.8.0. This issue arises from improper neutralization of data within XPath expressions, which can lead to uncontrolled resource consumption.

Impact

Exploitation of this vulnerability can cause uncontrolled resource consumption, potentially leading to a denial-of-service condition.

Remediation

Users are advised to upgrade to Apache HertzBeat version 1.8.0, which addresses this vulnerability.

Added: Feb 10, 2026, 11:14 AM
Updated: Feb 10, 2026, 4:27 PM

Vulnerability Rating

Custom Algorithm
spread
0.8
impact
2.5
exploitability
7.4
remediation
7.7
relevance
2.9
threat
0.0
urgency
2.9
incentive
4.2

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.