In Apache Dubbo prior to 2.7.8 (Apache org.apache.dubbo:dubbo) and prior to 2.6.9 (Alibaba com.alibaba:dubbo), the server indicates the serialization protocol to clients via a serialization ID, but the provider can be coerced into using an attacker-chosen serialization ID by tampering with the byte preamble flags (i.e., not following the server’s instructed serialization). If weak/unsafe deserializers such as Kryo or FST are present in the provider’s code scope/classpath (e.g., introduced via dependencies), a remote unauthenticated attacker can force the provider to deserialize attacker-controlled data using those deserializers, enabling exploitation of deserialization weaknesses.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a proof-of-concept exploit for CVE-2021-25641, a remote code execution vulnerability in Apache/Alibaba Dubbo <= 2.7.3 (and potentially <= 2.7.6 with different gadgets). The exploit is implemented in Java and consists of a Maven project with the main logic in 'Main.java' and supporting gadget/utility code in 'Utils.java'. The exploit crafts a malicious serialized object using FastJson and TemplatesImpl gadget chains, then sends it over a raw TCP connection to a Dubbo service (default port 20880). Upon successful exploitation, it executes arbitrary commands on the server: 'calc.exe' on Windows or 'touch /tmp/dubboexploited' on Linux, and prints 'whoops!' to the server console. The exploit is operational and can be adapted for different targets by changing the host, port, and command. The repository also includes a minimal Dubbo service interface for completeness. No detection or scanning functionality is present; this is a direct exploitation tool.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.