AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2021-36163

CRITICAL · CVSS 9.8 EPSS 2.90%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2021-09-07 · Last synced 2026-08-04

CyberRota Analysis

This is a critical severity vulnerability with a CVSS score of 9.8. It affects Apache.

CVE
CVE-2021-36163
Severity
CRITICAL
CVSS
9.8
EPSS
2.90%
Apache

Original NVD Description

In Apache Dubbo, users may choose to use the Hessian protocol. The Hessian protocol is implemented on top of HTTP and passes the body of a POST request directly to a HessianSkeleton: New HessianSkeleton are created without any configuration of the serialization factory and therefore without applying the dubbo properties for applying allowed or blocked type lists. In addition, the generic service is always exposed and therefore attackers do not need to figure out a valid service/method name pair. This is fixed in 2.7.13, 2.6.10.1

Related CVEs

Other vulnerabilities affecting the same vendor(s)