CVE-2019-17570: Apache XML-RPC
Critical severity, CVSS 9.8. EPSS: 49.3% chance of exploitation in the next 30 days.
An untrusted deserialization was found in the org.apache.xmlrpc.parser.XmlRpcResponseParser:addResult method of Apache XML-RPC (aka ws-xmlrpc) library. A malicious XML-RPC server could target a XML-RPC client causing it to execute arbitrary code. Apache XML-RPC is no longer maintained and this issue will not be fixed.
Affected products
- Apache XML-RPC: version 3.1 only; version 3.1.1 only; version 3.1.2 only; version 3.1.3 only
- Canonical Ubuntu Linux: version 16.04 only; version 18.04 only
- Debian Debian Linux: version 8.0 only; version 9.0 only; version 10.0 only
- Fedoraproject Fedora: version 31 only; version 32 only
- Red Hat Software Collections: version 1.0 only
Published 2020-01-23. Last modified 2026-06-17.