CVE-2023-33496: Xxl-RPC Project Xxl-RPC
Critical severity, CVSS 9.8. EPSS: 1% chance of exploitation in the next 30 days.
xxl-rpc v1.7.0 was discovered to contain a deserialization vulnerability via the component com.xxl.rpc.core.remoting.net.impl.netty.codec.NettyDecode#decode.
Affected products
- Xxl-RPC Project Xxl-RPC: up to and including 1.7.0
Published 2023-06-07. Last modified 2026-06-17.