← back
CVE-2021-25640CWE-918

Open Redirect or SSRF vulnerability usage of parseURL

3Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackepss 2.1%
exploitation probability
2.1%top 19% of all CVEs
observed exploitation
nono source reports it
In Apache Dubbo prior to 2.6.9 and 2.7.9, the usage of parseURL method will lead to the bypass of white host check which can cause open redirect or SSRF vulnerability.