AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2021-36161

CRITICAL · CVSS 9.8 EPSS 2.47%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2021-09-09 · Last synced 2026-08-04

CyberRota Analysis

AI analysis pending.

CVE
CVE-2021-36161
Severity
CRITICAL
CVSS
9.8
EPSS
2.47%
Apache

Original NVD Description

Some component in Dubbo will try to print the formated string of the input arguments, which will possibly cause RCE for a maliciously customized bean with special toString method. In the latest version, we fix the toString call in timeout, cache and some other places. Fixed in Apache Dubbo 2.7.13

Related CVEs

Other vulnerabilities affecting the same vendor(s)