CVE-2023-23638
Apache Dubbo Deserialization Vulnerability Gadgets Bypass
- Published
- Mar 8, 2023
- Updated
- Oct 23, 2024
- Assigning CNA
- apache
- Evidence observed
- Aug 8, 2026
Primary CVSS
nvd · CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HLow · next 30 days
- Percentile
- 91.6%
- Model date
- Sep 21, 2026
EPSS is a statistical estimate, not a certainty or a measure of impact. Combine it with CVSS, KEV status, exposure and your environment.
Summary
A deserialization vulnerability existed when dubbo generic invoke, which could lead to malicious code execution. This issue affects Apache Dubbo 2.7.x version 2.7.21 and prior versions; Apache Dubbo 3.0.x version 3.0.13 and prior versions; Apache Dubbo 3.1.x version 3.1.5 and prior versions.
Sources
4Apache Dubbo (CVE-2023-23638)漏洞利用的工程化实践
PoC exploit for Apache Dubbo CVE-2023-23638, a Hessian deserialization vulnerability enabling JNDI injection. Includes analysis articles and requires ZooKeeper and Java 8 for testing.
- CVE-2023-23638-ToolsExploit
Exploit tool for CVE-2023-23638, providing automated exploitation and payload generation for targeted vulnerability assessment and penetration testing.
Responsible use
Use vulnerability information only on systems you own or are authorized to test. Kitploit links to public research metadata and does not store exploit code or malicious payloads.