OCTOBER 5, 2026
Live Feed
Back to database
Case File

CVE-2019-17564

CRITICAL · CVSS 9.8 EPSS 35.32%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2020-04-01 · Last synced 2026-08-04

CyberRota Analysis

This is a critical severity vulnerability with a CVSS score of 9.8. It affects Apache, Java. Its EPSS score suggests a 35.3% probability of exploitation in the next 30 days.

CVE
CVE-2019-17564
Severity
CRITICAL
CVSS
9.8
EPSS
35.32%
Apache Java

Original NVD Description

Unsafe deserialization occurs within a Dubbo application which has HTTP remoting enabled. An attacker may submit a POST request with a Java object in it to completely compromise a Provider instance of Apache Dubbo, if this instance enables HTTP. This issue affected Apache Dubbo 2.7.0 to 2.7.4, 2.6.0 to 2.6.7, and all 2.5.x versions.

Related CVEs

Other vulnerabilities affecting the same vendor(s)