CVE-2023-33496: Xxl-RPC Project Xxl-RPC

Critical severity, CVSS 9.8. EPSS: 1% chance of exploitation in the next 30 days.

xxl-rpc v1.7.0 was discovered to contain a deserialization vulnerability via the component com.xxl.rpc.core.remoting.net.impl.netty.codec.NettyDecode#decode.

Affected products

Published 2023-06-07. Last modified 2026-06-17.