Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2020-26258

79
FAUCET Score

CVE-2020-26258 is a Server-Side Request Forgery (SSRF) vulnerability in the XStream Java library, affecting versions prior to 1.4.15, and impacting products like Apache, Debian, and Fedora that utilize it. This high-severity vulnerability (CVSS 7.7) allows an authenticated remote attacker to manipulate processed input streams to request data from internal, non-publicly available resources. While there is no evidence of active exploitation or public exploit code like Metasploit or ExploitDB, Nuclei templates exist for detection. The vulnerability has garnered minimal community discussion or media coverage.

Impacted Technologies

VendorProductVersion(s)CPE
< 6.0.0CPE matchmatch criteria
cpe:2.3:a:apache:struts:*:*:*:*:*:*:*:*
< 1.4.15CPE matchmatch criteria
cpe:2.3:a:xstream:xstream:*:*:*:*:*:*:*:*
9.0CPE matchmatch criteria
cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*
10.0CPE matchmatch criteria
cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*
33CPE matchmatch criteria
cpe:2.3:o:fedoraproject:fedora:33:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

6.3MEDIUM

CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N

Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
LOW
User Interaction
NONE
Scope
CHANGED
Confidentiality Impact
HIGH
Integrity Impact
NONE
Availability Impact
NONE
Exploitability Score
1.8
Impact Score
4.0
CvssVersion
3.1

Exploit Intelligence

EPSS Score
81.82%
Probability of exploitation in next 30 days
EPSS Percentile
99.6%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
Nuclei: CVE-2020-26258 · Mar 12, 2023
This CVE's current EPSS score of 0.8182 is in the 100th percentile among its peer group of 17,823 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (10)

mavenpatch availablevia ghsa
Product: com.thoughtworks.xstream:xstreamFixed in: 1.4.15
redhatpatch availablevia redhat_api
Product: Red Hat Data Grid 8.2.0Fixed in: xstream
View patch
redhatpatch availablevia redhat_api
Product: RHPAM 7.11.0Fixed in: xstream
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Integration
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Integration Camel Quarkus 2
View patch
redhatpatch availablevia redhat_api
Product: RHDM 7.11.0Fixed in: xstream
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Fuse 7.9Fixed in: xstream
View patch
github_advisoryworkaround availablevia nvd_reference
View patch
redhatno patchvia redhat_api
Product: Red Hat Integration Camel K 1Fixed in: xstream
redhatno patchvia redhat_api
Product: Red Hat Integration Camel Quarkus 1Fixed in: xstream

Vendor Advisories (2)

mavenGHSA-4cch-wxpw-8p28medium

Server-Side Forgery Request can be activated unmarshalling with XStream

Dec 21, 2020
redhatCVE-2020-26258Moderate

XStream: Server-Side Forgery Request vulnerability can be activated when unmarshalling

Dec 13, 2020

References

lists.apache.org / thread.html/r97993e3d78e1f5389b7b172ba9f308440830ce5f051ee62714a0aa34%40%3Ccommits.struts.apache.org%3E
Issue TrackingMailing List
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/22KVR6B5IZP3BGQ3HPWIO2FWWCKT3DHP
Mailing List
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/PVPHZA7VW2RRSDCOIPP2W6O5ND254TU7
Mailing List
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/QGXIU3YDPG6OGTDHMBLAFN7BPBERXREB
Mailing List
security.netapp.com / advisory/ntap-20210409-0005
Third Party Advisory
github.com / x-stream/xstream/security/advisories/GHSA-4cch-wxpw-8p28
MitigationThird Party Advisory
lists.apache.org / thread.html/r97993e3d78e1f5389b7b172ba9f308440830ce5f051ee62714a0aa34@%3Ccommits.struts.apache.org%3E
Issue TrackingMailing List
lists.debian.org / debian-lts-announce/2020/12/msg00042.html
Mailing ListThird Party Advisory
lists.fedoraproject.org / archives/list/[email protected]/message/22KVR6B5IZP3BGQ3HPWIO2FWWCKT3DHP
Mailing List
lists.fedoraproject.org / archives/list/[email protected]/message/PVPHZA7VW2RRSDCOIPP2W6O5ND254TU7
Mailing List
lists.fedoraproject.org / archives/list/[email protected]/message/QGXIU3YDPG6OGTDHMBLAFN7BPBERXREB
Mailing List
security.netapp.com / advisory/ntap-20210409-0005
Third Party Advisory
debian.org / security/2021/dsa-4828
Third Party Advisory
x-stream.github.io / CVE-2020-26258.html
ExploitMitigationThird Party Advisory