Xstream is a narrowly scoped but deeply embedded Java serialization library that enables object deserialization across a wide range of applications and frameworks, giving its vulnerability footprint disproportionate impact relative to its product count. Vulnerabilities in this library skew toward critical severity and frequently acquire public exploit code, reflecting both the memory-safety implications of unsafe deserialization and the library's role in security-sensitive data pipelines. The exposure clusters around deserialization of untrusted data as a foundational weakness, paired with recurrent classes including unrestricted file uploads, server-side request forgery, code injection, and OS command injection that arise when deserialized objects interact with the broader application context. Defenders should treat Xstream flaws as high-priority across their entire application inventory, as remediation often requires library upgrades rather than application-level mitigations alone; current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Xstream over time
Signals from CVEs in this vendor scope (37 CVEs).
37 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-39144HIGH XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker has sufficient rights to execute command | Aug 23, 2021 | 8.5 | 98 | YES | YES |
CVE-2013-7285CRITICAL Xstream API versions up to 1.4.6 and version 1.4.10, if the security framework has not been initialized, may allow a remote attacker to run arbitrary shell commands by manipulating | May 15, 2019 | 9.8 | 88 | NO | YES |
CVE-2021-21351CRITICAL XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability may allow a remote attacker to load and execute arb | Mar 23, 2021 | 9.1 | 82 | NO | YES |
CVE-2020-26217HIGH XStream before version 1.4.14 is vulnerable to Remote Code Execution.The vulnerability may allow a remote attacker to run arbitrary shell commands only by manipulating the processe | Nov 16, 2020 | 8.8 | 82 | NO | YES |
CVE-2019-10173CRITICAL It was found that xstream API version 1.4.10 before 1.4.11 introduced a regression for a previous deserialization flaw. If the security framework has not been initialized, it may a | Jul 23, 2019 | 9.8 | 81 | NO | NO |
CVE-2021-21345CRITICAL XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a remote attacker who has sufficien | Mar 23, 2021 | 9.9 | 80 | NO | YES |
CVE-2021-29505HIGH XStream is software for serializing Java objects to XML and back again. A vulnerability in XStream versions prior to 1.4.17 may allow a remote attacker has sufficient rights to exe | May 28, 2021 | 8.8 | 79 | NO | YES |
CVE-2020-26258HIGH XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.15, a Server-Side Forgery Request vulnerability can be activated when unmarshall | Dec 16, 2020 | 7.7 | 79 | NO | YES |
CVE-2021-21346CRITICAL XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a remote attacker to load and execu | Mar 23, 2021 | 9.8 | 74 | NO | NO |
CVE-2021-21344CRITICAL XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a remote attacker to load and execu | Mar 23, 2021 | 9.8 | 73 | NO | NO |
Signals from CVEs in this vendor scope (37 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Xstream.
Media articles that mention a CVE ID that affects a product developed by Xstream — matched by CVE ID, not by vendor name.