← Vulnerability feed

Vulnerability record · CVE-2021-30181 · published 1 June 2021

CVE-2021-30181: Apache Dubbo Script Routing Rule Enables Arbitrary Code Execution

Apache · Dubbo

Apache Dubbo versions prior to 2.6.9 and 2.7.9 support Script routing rules that are parsed and executed using ScriptEngine. Because the rule script is run by default, a crafted routing rule can execute arbitrary code. This matters because routing rules are part of the request path and the flaw is remotely reachable without authentication.

9.8 CVSS 3.1 Critical EPSS 61% · top 0.9%
9.8CVSS 3.1 base score, v2 7.5
61%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

Apache Dubbo prior to 2.6.9 and 2.7.9 supports Script routing which will enable a customer to route the request to the right server. These rules are used by the customers when making a request in order to find the right endpoint. When parsing these rules, Dubbo customers use ScriptEngine and run the rule provided by the script which by default may enable executing arbitrary code.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: medium.

critical priorityCVSS 9.8 with network reachability, no authentication, no user interaction and high EPSS make this a top remediation priority despite the absence of KEV listing.

What it is

Apache Dubbo versions prior to 2.6.9 and 2.7.9 support Script routing rules that are parsed and executed using ScriptEngine. Because the rule script is run by default, a crafted routing rule can execute arbitrary code. This matters because routing rules are part of the request path and the flaw is remotely reachable without authentication.

Impact

An attacker can execute arbitrary code in the context of the Dubbo process, leading to full compromise of confidentiality, integrity and availability. No privileges are required beyond the ability to supply or influence a routing rule.

Attack surface

The vulnerability is reachable over the network via the Dubbo routing rule mechanism, as reflected by the CVSS vector AV:N/PR:N/UI:N. No authentication or user interaction is required according to the vector and description.

Exploitation

The record does not list this CVE in CISA KEV and provides no exploit references, but EPSS is high at 0.60596 (99.1st percentile), indicating elevated likelihood of exploitation activity.

What to do

  • Upgrade Apache Dubbo to 2.6.9, 2.7.9 or later, which removes the unsafe default ScriptEngine execution of routing rules.
  • If immediate upgrade is not possible, disable or restrict Script routing rule support and avoid loading untrusted routing rules.
  • Restrict network access to Dubbo endpoints and admin/registry interfaces so untrusted clients cannot submit routing rules.
  • Review and sanitize any externally supplied routing rule configuration before it is parsed by Dubbo.
  • Monitor Dubbo logs and configuration changes for unexpected script-based routing rules.

Detection

  • Search Dubbo configuration and registry data for routing rules containing script or ScriptEngine content.
  • Monitor for unexpected child processes or command execution originating from the Dubbo service process.
  • Alert on anomalous outbound network connections from Dubbo hosts that may indicate post-exploitation activity.
  • Audit access logs for unauthenticated or unusual clients interacting with Dubbo routing rule interfaces.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2021-30181 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2023-29234Apache dubbo deserialization of untrusted data vulnerabilityA deserialization vulnerability existed when decode a malicious package.This issue affects Apache Dubbo: from 3.1.0 through 3.1.10, from 3.2.0 throug…EPSS 7.4%9.8CVE-2023-46279Apache dubbo deserialization of untrusted data vulnerabilityDeserialization of Untrusted Data vulnerability in Apache Dubbo.This issue only affects Apache Dubbo 3.1.5. Users are recommended to upgrade to the l…EPSS 1.7%9.8CVE-2023-23638Apache dubbo deserialization of untrusted data vulnerabilityA deserialization vulnerability existed when dubbo generic invoke, which could lead to malicious code execution. This issue affects Apache Dubbo 2.7.…EPSS 4.8%9.8CVE-2021-32824Apache dubbo deserialization of untrusted data vulnerabilityApache Dubbo is a java based, open source RPC framework. Versions prior to 2.6.10 and 2.7.10 are vulnerable to pre-auth remote code execution via arb…EPSS 2.8%9.8CVE-2022-39198Apache dubbo deserialization of untrusted data vulnerabilityA deserialization vulnerability existed in dubbo hessian-lite 3.2.12 and its earlier versions, which could lead to malicious code execution. This iss…EPSS 2.6%9.8CVE-2021-43297Apache dubbo deserialization of untrusted data vulnerabilityA deserialization vulnerability existed in dubbo hessian-lite 3.2.11 and its earlier versions, which could lead to malicious code execution. Most Dub…EPSS 17%9.8CVE-2021-37579Apache dubbo deserialization of untrusted data vulnerabilityThe Dubbo Provider will check the incoming request and the corresponding serialization type of this request meet the configuration set by the server.…EPSS 6.6%9.8CVE-2021-36161Apache dubbo vulnerabilitySome component in Dubbo will try to print the formated string of the input arguments, which will possibly cause RCE for a maliciously customized bean…EPSS 2.5%

Source: NIST National Vulnerability Database (record CVE-2021-30181), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.