CVE-2024-42362: Apache Hertzbeat

High severity, CVSS 8.8. EPSS: 1.3% chance of exploitation in the next 30 days.

Hertzbeat is an open source, real-time monitoring system. Hertzbeat has an authenticated (user role) RCE via unsafe deserialization in /api/monitors/import. This vulnerability is fixed in 1.6.0.

Affected products

  • Apache Hertzbeat: before 1.6.0 (fixed in 1.6.0)

Published 2024-08-20. Last modified 2026-06-17.