Critical severity9.8NVD Advisory· Published Sep 9, 2021· Updated Jun 17, 2026
CVE-2021-36161
CVE-2021-36161
Description
Some component in Dubbo will try to print the formated string of the input arguments, which will possibly cause RCE for a maliciously customized bean with special toString method. In the latest version, we fix the toString call in timeout, cache and some other places. Fixed in Apache Dubbo 2.7.13
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
org.apache.dubbo:dubboMaven | < 2.7.13 | 2.7.13 |
Affected products
3- Apache Software Foundation/Apache Dubbov5Range: Apache Dubbo 2.7.x
Patches
Vulnerability mechanics
References
3- github.com/advisories/GHSA-qvm7-23cj-437vghsaADVISORY
- lists.apache.org/thread.html/r40212261fd5d638074b65f22ac73eebe93ace310c79d4cfcca4863da%40%3Cdev.dubbo.apache.org%3EnvdMailing ListVendor AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2021-36161ghsaADVISORY
News mentions
0No linked articles in our index yet.