← Vulnerability feed

Vulnerability record · CVE-2021-32824 · published 3 January 2023

CVE-2021-32824: Apache dubbo deserialization of untrusted data vulnerability

Apache · Dubbo

Apache Dubbo is a java based, open source RPC framework. Versions prior to 2.6.10 and 2.7.10 are vulnerable to pre-auth remote code execution via arbitrary bean manipulation in the Telnet handler. The Dubbo main service port can be used to access a Telnet Handler which offers some basic methods to collect information about the providers and methods exposed by the service and it can even allow to shutdown the service. This endpoint is unprotected. Additionally, a provider method can be invoked using the `invoke` handler. This handler uses a safe version of FastJson to process the call arguments. However, the resulting list is later processed with `PojoUtils.realize` which can be used to instantiate arbitrary classes and invoke its setters. Even though FastJson is properly protected with a default blocklist, `PojoUtils.realize` is not, and an attacker can leverage that to achieve remote code execution. Versions 2.6.10 and 2.7.10 contain fixes for this issue.

9.8 CVSS 3.1 Critical EPSS 2.8% · top 13.9% CWE-502 · Deserialization of untrusted data
9.8CVSS 3.1 base score
2.8%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

Apache Dubbo is a java based, open source RPC framework. Versions prior to 2.6.10 and 2.7.10 are vulnerable to pre-auth remote code execution via arbitrary bean manipulation in the Telnet handler. The Dubbo main service port can be used to access a Telnet Handler which offers some basic methods to collect information about the providers and methods exposed by the service and it can even allow to shutdown the service. This endpoint is unprotected. Additionally, a provider method can be invoked using the `invoke` handler. This handler uses a safe version of FastJson to process the call arguments. However, the resulting list is later processed with `PojoUtils.realize` which can be used to instantiate arbitrary classes and invoke its setters. Even though FastJson is properly protected with a default blocklist, `PojoUtils.realize` is not, and an attacker can leverage that to achieve remote code execution. Versions 2.6.10 and 2.7.10 contain fixes for this issue.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2021-32824 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2023-29234Apache dubbo deserialization of untrusted data vulnerabilityA deserialization vulnerability existed when decode a malicious package.This issue affects Apache Dubbo: from 3.1.0 through 3.1.10, from 3.2.0 throug…EPSS 7.4%9.8CVE-2023-46279Apache dubbo deserialization of untrusted data vulnerabilityDeserialization of Untrusted Data vulnerability in Apache Dubbo.This issue only affects Apache Dubbo 3.1.5. Users are recommended to upgrade to the l…EPSS 1.7%9.8CVE-2023-23638Apache dubbo deserialization of untrusted data vulnerabilityA deserialization vulnerability existed when dubbo generic invoke, which could lead to malicious code execution. This issue affects Apache Dubbo 2.7.…EPSS 4.8%9.8CVE-2022-39198Apache dubbo deserialization of untrusted data vulnerabilityA deserialization vulnerability existed in dubbo hessian-lite 3.2.12 and its earlier versions, which could lead to malicious code execution. This iss…EPSS 2.6%9.8CVE-2021-43297Apache dubbo deserialization of untrusted data vulnerabilityA deserialization vulnerability existed in dubbo hessian-lite 3.2.11 and its earlier versions, which could lead to malicious code execution. Most Dub…EPSS 17%9.8CVE-2021-37579Apache dubbo deserialization of untrusted data vulnerabilityThe Dubbo Provider will check the incoming request and the corresponding serialization type of this request meet the configuration set by the server.…EPSS 6.6%9.8CVE-2021-36161Apache dubbo vulnerabilitySome component in Dubbo will try to print the formated string of the input arguments, which will possibly cause RCE for a maliciously customized bean…EPSS 2.5%9.8CVE-2021-36163Apache dubbo deserialization of untrusted data vulnerabilityIn Apache Dubbo, users may choose to use the Hessian protocol. The Hessian protocol is implemented on top of HTTP and passes the body of a POST reque…EPSS 3.3%

Source: NIST National Vulnerability Database (record CVE-2021-32824), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.