CVE-2019-17564: Apache Dubbo
Critical severity, CVSS 9.8. EPSS: 36.5% chance of exploitation in the next 30 days.
Unsafe deserialization occurs within a Dubbo application which has HTTP remoting enabled. An attacker may submit a POST request with a Java object in it to completely compromise a Provider instance of Apache Dubbo, if this instance enables HTTP. This issue affected Apache Dubbo 2.7.0 to 2.7.4, 2.6.0 to 2.6.7, and all 2.5.x versions.
Affected products
- Apache Dubbo: from 2.5.0, up to and including 2.5.10; from 2.6.0, up to and including 2.6.7; from 2.7.0, up to and including 2.7.4
Published 2020-04-01. Last modified 2026-06-17.