CVE-2019-17570: Apache XML-RPC

Critical severity, CVSS 9.8. EPSS: 49.3% chance of exploitation in the next 30 days.

An untrusted deserialization was found in the org.apache.xmlrpc.parser.XmlRpcResponseParser:addResult method of Apache XML-RPC (aka ws-xmlrpc) library. A malicious XML-RPC server could target a XML-RPC client causing it to execute arbitrary code. Apache XML-RPC is no longer maintained and this issue will not be fixed.

Affected products

  • Apache XML-RPC: version 3.1 only; version 3.1.1 only; version 3.1.2 only; version 3.1.3 only
  • Canonical Ubuntu Linux: version 16.04 only; version 18.04 only
  • Debian Debian Linux: version 8.0 only; version 9.0 only; version 10.0 only
  • Fedoraproject Fedora: version 31 only; version 32 only
  • Red Hat Software Collections: version 1.0 only

Published 2020-01-23. Last modified 2026-06-17.