CVE-2025-24016·Python vulnerability
Wazuh is a free and open source platform used for threat prevention, detection, and response. Starting in version 4.4.0 and prior to version 4.9.1, an unsafe deserialization vulnerability allows for remote code execution on Wazuh servers. DistributedAPI parameters are a serialized as JSON and deserialized using `as_wazuh_object` (in `framework/wazuh/core/cluster/common.py`). If an attacker manages to inject an unsanitized dictionary in DAPI request/response, they can forge an unhandled exception (`__unhandled_exc__`) to evaluate arbitrary python code. The vulnerability can be triggered by anybody with API access (compromised dashboard or Wazuh servers in the cluster) or, in certain configurations, even by a compromised agent. Version 4.9.1 contains a fix.
- Severity
- critical
- Software
- Python
- Fixed in
- 4.9.1
- Published
- 2025-02-10
Affected versions
From: 4.4.0
Until: 4.9.1
Fixed in: 4.9.1
How to fix this CVE
Upgrade Wazuh to version 4.9.1 or later to patch the unsafe deserialization vulnerability in the DistributedAPI component. This critical flaw allows authenticated attackers to execute arbitrary Python code through malicious dictionary injection. Immediately apply this update if you are running Wazuh 4.4.0 through 4.9.0, especially if your Wazuh dashboard or cluster agents are exposed to untrusted networks.
sudo dnf check-update && sudo dnf upgrade wazuh-manager wazuh-agent wazuh-dashboardDefensia detects this vulnerability
What an exploitation attempt looks like
Sample log line indicative of exploitation attempts:
POST requests to Wazuh DistributedAPI endpoints containing serialized Python objects with __unhandled_exc__ fields; log entries showing "Traceback" or "Exception" errors immediately following DistributedAPI requests; unusual exception handling in /var/ossec/logs/cluster.log referencing deserialization or __unhandled_exc__WAF mitigation (if patching is not yet possible)
Add this rule to your WAF to block exploitation attempts while you schedule the patch.
Implement request filtering to block DistributedAPI requests containing serialized Python object patterns (e.g., __unhandled_exc__, __reduce__, __getstate__); restrict API access via IP allowlisting; enforce mutual TLS authentication between cluster nodesHow to check if you are affected
- Check Wazuh version: wazuh-control info | grep 'Version' or cat /var/ossec/etc/ossec.conf | grep -i version
- Verify API exposure: curl -s https://localhost:55000/version -u admin:admin -k | grep -o '"version":"[^"]*"' (confirm version is below 4.9.1)
- Search Wazuh logs for deserialization errors: grep -r '__unhandled_exc__' /var/ossec/logs/ /var/log/wazuh/ 2>/dev/null
- After patching, confirm upgrade: wazuh-control info | grep 'Version' and verify it shows 4.9.1 or higher
FAQ
What is CVE-2025-24016?
CVE-2025-24016 is an unsafe deserialization vulnerability in Wazuh's DistributedAPI that permits remote code execution when attackers inject crafted dictionary objects into API requests or responses, allowing them to execute arbitrary Python code on affected Wazuh servers.
Is CVE-2025-24016 being actively exploited?
Yes, CVE-2025-24016 is listed in the CISA Known Exploited Vulnerabilities (KEV) catalog and is being actively exploited in the wild, making immediate patching critical.
What versions of Wazuh are affected by CVE-2025-24016?
Wazuh versions 4.4.0 through 4.9.0 (inclusive) are vulnerable. Version 4.9.1 and later contain the fix.
How do I check if my server is vulnerable to CVE-2025-24016?
Run 'wazuh-control info | grep Version' or inspect /var/ossec/etc/ossec.conf; if the version is between 4.4.0 and 4.9.0, your installation is vulnerable.
Does Defensia detect CVE-2025-24016?
Yes — Defensia's CVE advisory scanner compares installed Wazuh package versions against the NVD database. If a vulnerable Wazuh instance is detected on a monitored server, CVE-2025-24016 will appear in your dashboard with remediation steps.
Related Python CVEs
References
Track CVEs across your fleet automatically
Defensia scans your Linux servers and tells you exactly which ones are running vulnerable versions — including CVE-2025-24016. Free for 1 server.
Get started free