In Apache Dubbo prior to 2.6.9 and 2.7.9, the usage of parseURL method will lead to the bypass of white host check which can cause open redirect or SSRF vulnerability.
[
{
"target": {
"file": "dubbo-common/src/test/java/org/apache/dubbo/common/config/configcenter/file/FileSystemDynamicConfigurationTest.java"
},
"id": "CVE-2021-25640-3d627d1b",
"signature_type": "Line",
"digest": {
"threshold": 0.9,
"line_hashes": [
"72231841111284800912350994376866121705",
"233033215338957908405456124231437903882",
"140637230428003596141285701283888105322",
"242445828973537834571438162558293632628",
"128209080924491398941326372106185479564",
"188231531121655282626969011487258186775",
"257956046854501751713743115390337990601",
"336322483333952764955930788721313603908",
"219322293503094885880181465372795833844",
"265727845774569082676072385296020006034"
]
},
"signature_version": "v1",
"source": "https://github.com/apache/dubbo/commit/f0483b80a32e813a4393879744e30d0084c3eafd",
"deprecated": false
}
]
"2026-07-09T00:12:59Z"
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-25640.json"