CVE-2019-17564: Apache Dubbo

Critical severity, CVSS 9.8. EPSS: 36.5% chance of exploitation in the next 30 days.

Unsafe deserialization occurs within a Dubbo application which has HTTP remoting enabled. An attacker may submit a POST request with a Java object in it to completely compromise a Provider instance of Apache Dubbo, if this instance enables HTTP. This issue affected Apache Dubbo 2.7.0 to 2.7.4, 2.6.0 to 2.6.7, and all 2.5.x versions.

Affected products

  • Apache Dubbo: from 2.5.0, up to and including 2.5.10; from 2.6.0, up to and including 2.6.7; from 2.7.0, up to and including 2.7.4

Published 2020-04-01. Last modified 2026-06-17.