{"id":"CVE-2021-25640","details":"In Apache Dubbo prior to 2.6.9 and 2.7.9, the usage of parseURL method will lead to the bypass of white host check which can cause open redirect or SSRF vulnerability.","aliases":["GHSA-gw4j-4229-q4px"],"modified":"2026-07-09T00:12:59.673822Z","published":"2021-06-01T14:15:09.693Z","references":[{"type":"ADVISORY","url":"https://lists.apache.org/thread.html/re4cab8855361a454d2af106fb3dad76259e723015fd7e09cb4f9eb77%40%3Cdev.dubbo.apache.org%3E"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/apache/dubbo","events":[{"introduced":"31ca18c712de2016795ba59f499f7c254f9281d5"},{"fixed":"d895bf15d0dda6a69c552c6b06d5e452692bef53"},{"introduced":"614bcebc01336ee5047a98f96b28915680c0399c"},{"fixed":"f0483b80a32e813a4393879744e30d0084c3eafd"}],"database_specific":{"cpe":"cpe:2.3:a:apache:dubbo:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"2.5.0"},{"fixed":"2.6.9"},{"introduced":"2.7.0"},{"fixed":"2.7.9"}],"source":"CPE_RANGE"}}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-25640.json","vanir_signatures_modified":"2026-07-09T00:12:59Z","vanir_signatures":[{"id":"CVE-2021-25640-3d627d1b","signature_type":"Line","signature_version":"v1","source":"https://github.com/apache/dubbo/commit/f0483b80a32e813a4393879744e30d0084c3eafd","target":{"file":"dubbo-common/src/test/java/org/apache/dubbo/common/config/configcenter/file/FileSystemDynamicConfigurationTest.java"},"deprecated":false,"digest":{"line_hashes":["72231841111284800912350994376866121705","233033215338957908405456124231437903882","140637230428003596141285701283888105322","242445828973537834571438162558293632628","128209080924491398941326372106185479564","188231531121655282626969011487258186775","257956046854501751713743115390337990601","336322483333952764955930788721313603908","219322293503094885880181465372795833844","265727845774569082676072385296020006034"],"threshold":0.9}}]}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"}]}