Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Xstream

First CVE: May 17, 2016Active for: 10 yearsTotal CVEs: 37
91.9
VTI Score
TOP TARGET

Xstream is a narrowly scoped but deeply embedded Java serialization library that enables object deserialization across a wide range of applications and frameworks, giving its vulnerability footprint disproportionate impact relative to its product count. Vulnerabilities in this library skew toward critical severity and frequently acquire public exploit code, reflecting both the memory-safety implications of unsafe deserialization and the library's role in security-sensitive data pipelines. The exposure clusters around deserialization of untrusted data as a foundational weakness, paired with recurrent classes including unrestricted file uploads, server-side request forgery, code injection, and OS command injection that arise when deserialized objects interact with the broader application context. Defenders should treat Xstream flaws as high-priority across their entire application inventory, as remediation often requires library upgrades rather than application-level mitigations alone; current exploitation activity and exposure counts are shown alongside this summary.

FAUCET AI Generated
37
Total CVEs
More Total CVEs than 98% of tracked vendors
6.2
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 98% of tracked vendors
8.4
Avg CVSS Score
Higher Avg CVSS Score than 82% of tracked vendors
2.7%
In CISA KEV
Higher KEV Rate than 99% of tracked vendors

Trends Over Time

The number and severity of CVEs published that impact products developed by Xstream over time

Volume of CVEsAvg CVSS Base Score
First CVE
May 17, 2016
10 years ago
Most Recent CVE
Dec 28, 2022
1,304 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (37 CVEs).

37 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2021-39144HIGH
XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker has sufficient rights to execute command
Aug 23, 20218.598YESYES
CVE-2013-7285CRITICAL
Xstream API versions up to 1.4.6 and version 1.4.10, if the security framework has not been initialized, may allow a remote attacker to run arbitrary shell commands by manipulating
May 15, 20199.888NOYES
CVE-2021-21351CRITICAL
XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability may allow a remote attacker to load and execute arb
Mar 23, 20219.182NOYES
CVE-2020-26217HIGH
XStream before version 1.4.14 is vulnerable to Remote Code Execution.The vulnerability may allow a remote attacker to run arbitrary shell commands only by manipulating the processe
Nov 16, 20208.882NOYES
CVE-2019-10173CRITICAL
It was found that xstream API version 1.4.10 before 1.4.11 introduced a regression for a previous deserialization flaw. If the security framework has not been initialized, it may a
Jul 23, 20199.881NONO
CVE-2021-21345CRITICAL
XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a remote attacker who has sufficien
Mar 23, 20219.980NOYES
CVE-2021-29505HIGH
XStream is software for serializing Java objects to XML and back again. A vulnerability in XStream versions prior to 1.4.17 may allow a remote attacker has sufficient rights to exe
May 28, 20218.879NOYES
CVE-2020-26258HIGH
XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.15, a Server-Side Forgery Request vulnerability can be activated when unmarshall
Dec 16, 20207.779NOYES
CVE-2021-21346CRITICAL
XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a remote attacker to load and execu
Mar 23, 20219.874NONO
CVE-2021-21344CRITICAL
XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a remote attacker to load and execu
Mar 23, 20219.873NONO
View all 37 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products37 CVEs
70%
24%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network37 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low23 (62.2%)
High14 (37.8%)
Unknown0 (0.0%)
User Interaction
None37 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low18 (48.6%)
High1 (2.7%)
None18 (48.6%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (37 CVEs).

CISA KEV
1 CVE
2.7% of CVEs· 99th percentile
Metasploit
1 CVE
2.7% of CVEs· 97th percentile
Nuclei
10 CVEs
27.0% of CVEs· 98th percentile
ExploitDB
1 CVE
2.7% of CVEs· 74th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Xstream.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Xstream — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Xstream's Products

View all 4 CNAs →

Top CWEs