CVE-2023-46279: Apache Dubbo

Critical severity, CVSS 9.8. EPSS: 1.7% chance of exploitation in the next 30 days.

Deserialization of Untrusted Data vulnerability in Apache Dubbo.This issue only affects Apache Dubbo 3.1.5. Users are recommended to upgrade to the latest version, which fixes the issue.

Affected products

  • Apache Dubbo: version 3.1.5 only

Published 2023-12-15. Last modified 2026-06-17.