CVE-2025-13426: Improper Sandboxing in Google Apigee's JavaCallout Policy Allows for Remote Code Execution
A vulnerability exists in Google Apigee's JavaCallout policy https://docs.apigee.com/api-platform/reference/policies/java-callout-policy that allows for remote code execution.
It is possible for a user to write a JavaCallout that injected a malicious object into the MessageContext to execute arbitrary Java code and system commands at runtime, leading to unauthorized access to data, lateral movement within the network, and access to backend systems.
The Apigee hybrid versions below have all been updated to protect from this vulnerability: Hybrid1.11.2+ Hybrid1.12.4+ Hybrid1.13.3+ Hybrid1.14.1+ OPDK5202+ OPDK5300+
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Google Apigee Hybridto a version that resolves this vulnerability.Fixed in 1.11.2+ - Upgrade
Upgrade
Google Apigee Hybridto a version that resolves this vulnerability.Fixed in 1.12.4+ - Upgrade
Upgrade
Google Apigee Hybridto a version that resolves this vulnerability.Fixed in 1.13.3+ - Upgrade
Upgrade
Google Apigee Hybridto a version that resolves this vulnerability.Fixed in 1.14.1+ - Upgrade
Upgrade
Google Apigee OPDKto a version that resolves this vulnerability.Fixed in 5202+ - Upgrade
Upgrade
Google Apigee OPDKto a version that resolves this vulnerability.Fixed in 5300+
Event History
Frequently Asked Questions
What is the severity of CVE-2025-13426?
CVE-2025-13426 has a high severity due to its potential for remote code execution.
How do I fix CVE-2025-13426?
To fix CVE-2025-13426, upgrade Google Apigee to the latest version above 1.14.1.
What versions of Google Apigee are affected by CVE-2025-13426?
Google Apigee versions prior to 1.14.2 are affected by CVE-2025-13426.
What kind of exploit does CVE-2025-13426 enable?
CVE-2025-13426 enables remote code execution, allowing attackers to run arbitrary code on the server.
Who is the vendor of the software affected by CVE-2025-13426?
The vendor of the affected software is Google, specifically for Google Apigee.