← Vulnerability feed

Vulnerability record · CVE-2021-30180 · published 1 June 2021

CVE-2021-30180: Apache Dubbo YAML tag routing enables arbitrary constructor calls

Apache · Dubbo

Apache Dubbo before 2.7.9 parses YAML tag routing rules that can cause arbitrary constructors to be invoked. Because these rules are processed when customers make requests to locate endpoints, a malicious or tampered rule set can trigger unintended object instantiation inside the Dubbo process. The record gives no further detail on the exact constructor reachability or required preconditions.

9.8 CVSS 3.1 Critical EPSS 60% · top 0.9% CWE-444 · HTTP request smuggling
9.8CVSS 3.1 base score, v2 6.8
60%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

Apache Dubbo prior to 2.7.9 support Tag routing which will enable a customer to route the request to the right server. These rules are used by the customers when making a request in order to find the right endpoint. When parsing these YAML rules, Dubbo customers may enable calling arbitrary constructors.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: medium.

critical priorityCVSS 9.8 with network reachability, no authentication and no user interaction, plus a very high EPSS percentile, makes this a top remediation priority despite the absence of KEV listing.

What it is

Apache Dubbo before 2.7.9 parses YAML tag routing rules that can cause arbitrary constructors to be invoked. Because these rules are processed when customers make requests to locate endpoints, a malicious or tampered rule set can trigger unintended object instantiation inside the Dubbo process. The record gives no further detail on the exact constructor reachability or required preconditions.

Impact

An attacker who can influence the YAML routing rules could cause arbitrary constructors to run, potentially leading to code execution or full compromise of the Dubbo service. The CVSS vector rates confidentiality, integrity and availability impact as high.

Attack surface

The flaw is reached over the network through Dubbo's tag routing rule handling, per the CVSS vector AV:N/AC:L/PR:N/UI:N, meaning no authentication or user interaction is required. The description does not specify whether the attacker must already be able to supply routing rules or whether a default configuration exposes this path.

Exploitation

CVE-2021-30180 is not listed in CISA KEV, but EPSS is high at roughly 0.60 probability (99th percentile), indicating elevated likelihood of exploitation activity. The only references are Apache mailing list advisories, with no public exploit or in-the-wild reporting noted in the record.

What to do

  • Upgrade Apache Dubbo to 2.7.9 or later, which is the version boundary stated in the advisory.
  • Restrict who can create or modify tag routing YAML rules and treat rule sources as trusted input.
  • Disable or avoid tag routing if it is not required for your deployment.
  • Monitor Dubbo configuration and rule repositories for unauthorized changes.
  • Apply network controls so Dubbo endpoints are not reachable from untrusted networks.

Detection

  • Alert on unexpected constructor or class-loading activity in Dubbo service logs and JVM telemetry.
  • Monitor for changes to Dubbo tag routing YAML files or rule sources outside normal change windows.
  • Hunt for Dubbo versions below 2.7.9 in asset inventories and correlate with external exposure.
  • Review network logs for unusual inbound traffic to Dubbo service ports from untrusted sources.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2021-30180 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2023-29234Apache dubbo deserialization of untrusted data vulnerabilityA deserialization vulnerability existed when decode a malicious package.This issue affects Apache Dubbo: from 3.1.0 through 3.1.10, from 3.2.0 throug…EPSS 7.4%9.8CVE-2023-46279Apache dubbo deserialization of untrusted data vulnerabilityDeserialization of Untrusted Data vulnerability in Apache Dubbo.This issue only affects Apache Dubbo 3.1.5. Users are recommended to upgrade to the l…EPSS 1.7%9.8CVE-2023-23638Apache dubbo deserialization of untrusted data vulnerabilityA deserialization vulnerability existed when dubbo generic invoke, which could lead to malicious code execution. This issue affects Apache Dubbo 2.7.…EPSS 4.8%9.8CVE-2021-32824Apache dubbo deserialization of untrusted data vulnerabilityApache Dubbo is a java based, open source RPC framework. Versions prior to 2.6.10 and 2.7.10 are vulnerable to pre-auth remote code execution via arb…EPSS 2.8%9.8CVE-2022-39198Apache dubbo deserialization of untrusted data vulnerabilityA deserialization vulnerability existed in dubbo hessian-lite 3.2.12 and its earlier versions, which could lead to malicious code execution. This iss…EPSS 2.6%9.8CVE-2021-43297Apache dubbo deserialization of untrusted data vulnerabilityA deserialization vulnerability existed in dubbo hessian-lite 3.2.11 and its earlier versions, which could lead to malicious code execution. Most Dub…EPSS 17%9.8CVE-2021-37579Apache dubbo deserialization of untrusted data vulnerabilityThe Dubbo Provider will check the incoming request and the corresponding serialization type of this request meet the configuration set by the server.…EPSS 6.6%9.8CVE-2021-36161Apache dubbo vulnerabilitySome component in Dubbo will try to print the formated string of the input arguments, which will possibly cause RCE for a maliciously customized bean…EPSS 2.5%

Source: NIST National Vulnerability Database (record CVE-2021-30180), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.