CVE Vulnerabilities

CVE-2025-13426

Improper Control of Dynamically-Managed Code Resources

Published: Dec 05, 2025 | Modified: Dec 05, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

A vulnerability exists in Google Apigees JavaCallout policy https://docs.apigee.com/api-platform/reference/policies/java-callout-policy that allows for remote code execution.

It is possible for a user to write a JavaCallout that injected a malicious object into the MessageContext to execute arbitrary Java code and system commands at runtime, leading to unauthorized access to data, lateral movement within the network, and access to backend systems.

The Apigee hybrid versions below have all been updated to protect from this vulnerability:

  • Hybrid_1.11.2+
  • Hybrid_1.12.4+
  • Hybrid_1.13.3+
  • Hybrid_1.14.1+
  • OPDK_5202+
  • OPDK_5300+

Weakness

The product does not properly restrict reading from or writing to dynamically-managed code resources such as variables, objects, classes, attributes, functions, or executable instructions or statements.

Potential Mitigations

References