Sofastack's vulnerability footprint is concentrated in its RPC framework product, with the durable signal centered on deserialization and expression-language injection risks that reflect the data-handling and template-processing complexity inherent to a serialization-based middleware platform. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Sofastack over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-41331CRITICAL SOFARPC is a Java RPC framework. Versions prior to 5.11.0 are vulnerable to remote command execution. Through a carefully
crafted payload, an attacker can achieve JNDI injection or | Sep 12, 2023 | 9.8 | 29 | NO | NO |
CVE-2024-23636CRITICAL SOFARPC is a Java RPC framework. SOFARPC defaults to using the SOFA Hessian protocol to deserialize received data, while the SOFA Hessian protocol uses a blacklist mechanism to res | Jan 23, 2024 | 9.8 | 26 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Sofastack.
Media articles that mention a CVE ID that affects a product developed by Sofastack — matched by CVE ID, not by vendor name.