← Back to browse · API

CVE-2022-39198

Severity
CRITICAL
CVSS
9.8
EPSS
0.02428
Risk score
40.05
CISA KEV
No
PoC
No
Published
2022-10-18
Modified
2025-05-13
First seen
2026-08-07
Aliases
EUVD-2022-7031, GHSA-5QWQ-G2HX-R6F7
Products
Apache Software Foundation:Apache Dubbo Apache Dubbo 2.7.x ≤2.7.17, Apache Software Foundation:Apache Dubbo Apache Dubbo 3.0.x ≤3.0.11, Apache Software Foundation:Apache Dubbo Apache Dubbo 3.1.x ≤3.1.0
Sources
euvd EUVD-2022-7031

Description

A deserialization vulnerability existed in dubbo hessian-lite 3.2.12 and its earlier versions, which could lead to malicious code execution. This issue affects Apache Dubbo 2.7.x version 2.7.17 and prior versions; Apache Dubbo 3.0.x version 3.0.11 and prior versions; Apache Dubbo 3.1.x version 3.1.0 and prior versions.

References