{"id":"CVE-2021-39140","title":"XStream is a simple library to serialize objects to XML and back again","summary":"XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to allocate 100% CPU time on the target system depending on CPU type or parallel execution of suc…","severity":"medium","cvss":6.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","cwe":["CWE-502","CWE-835"],"vendor":"xstream","product":"xstream","affected":["xstream < 1.4.18","debian_linux = 9.0","debian_linux = 10.0","debian_linux = 11.0","fedora = 33","fedora = 34","fedora = 35","snapmanager","business_activity_monitoring = 12.2.1.4.0","commerce_guided_search = 11.3.2","communications_billing_and_revenue_management_elastic_charging_engine = 11.3","communications_billing_and_revenue_management_elastic_charging_engine = 12.0","communications_cloud_native_core_automated_test_suite = 1.9.0","communications_cloud_native_core_binding_support_function = 1.10.0","communications_cloud_native_core_policy = 1.14.0","communications_unified_inventory_management = 7.3.4","communications_unified_inventory_management = 7.3.5","communications_unified_inventory_management = 7.4.0","communications_unified_inventory_management = 7.4.1","communications_unified_inventory_management = 7.4.2","retail_xstore_point_of_service = 16.0.6","retail_xstore_point_of_service = 17.0.4","retail_xstore_point_of_service = 18.0.3","retail_xstore_point_of_service = 19.0.2","retail_xstore_point_of_service = 20.0.1","utilities_framework = 4.2.0.2.0","utilities_framework = 4.2.0.3.0","utilities_framework = 4.3.0.1.0","utilities_framework = 4.3.0.6.0","utilities_framework = 4.4.0.0.0","utilities_framework = 4.4.0.2.0","utilities_framework = 4.4.0.3.0","utilities_testing_accelerator = 6.0.0.1.1","webcenter_portal = 12.2.1.3.0","webcenter_portal = 12.2.1.4.0"],"patched":["xstream 1.4.18"],"published":"2021-08-23","updated":"2026-10-07","sourceUpdated":"2026-10-07T21:17:03.583","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2021-39140","references":[{"url":"https://github.com/x-stream/xstream/security/advisories/GHSA-6wf9-jmg9-vxcc","label":"security-advisories@github.com"},{"url":"https://lists.debian.org/debian-lts-announce/2021/09/msg00017.html","label":"security-advisories@github.com"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/22KVR6B5IZP3BGQ3HPWIO2FWWCKT3DHP/","label":"security-advisories@github.com"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/PVPHZA7VW2RRSDCOIPP2W6O5ND254TU7/","label":"security-advisories@github.com"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/QGXIU3YDPG6OGTDHMBLAFN7BPBERXREB/","label":"security-advisories@github.com"},{"url":"https://security.netapp.com/advisory/ntap-20210923-0003/","label":"security-advisories@github.com"},{"url":"https://www.debian.org/security/2021/dsa-5004","label":"security-advisories@github.com"},{"url":"https://www.oracle.com/security-alerts/cpuapr2022.html","label":"security-advisories@github.com"},{"url":"https://www.oracle.com/security-alerts/cpujan2022.html","label":"security-advisories@github.com"},{"url":"https://www.oracle.com/security-alerts/cpujul2022.html","label":"security-advisories@github.com"},{"url":"https://x-stream.github.io/CVE-2021-39140.html","label":"security-advisories@github.com"},{"url":"https://github.com/x-stream/xstream/security/advisories/GHSA-6wf9-jmg9-vxcc","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.debian.org/debian-lts-announce/2021/09/msg00017.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/22KVR6B5IZP3BGQ3HPWIO2FWWCKT3DHP/","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/PVPHZA7VW2RRSDCOIPP2W6O5ND254TU7/","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/QGXIU3YDPG6OGTDHMBLAFN7BPBERXREB/","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://security.netapp.com/advisory/ntap-20210923-0003/","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.debian.org/security/2021/dsa-5004","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.oracle.com/security-alerts/cpuapr2022.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.oracle.com/security-alerts/cpujan2022.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.oracle.com/security-alerts/cpujul2022.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://x-stream.github.io/CVE-2021-39140.html","label":"af854a3a-2127-422b-91ae-364da2661108"}],"tags":["nvd","cve.org"],"epss":0.05918,"epssPercentile":0.93054,"ssvc":{"exploitation":"none","automatable":"yes","technicalImpact":"partial","timestamp":"2026-10-07T20:00:19.004141Z"},"ingestedAt":"2026-10-07T20:46:47.002Z","slug":"CVE-2021-39140","body":"## Overview\n\nXStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to allocate 100% CPU time on the target system depending on CPU type or parallel execution of such a payload resulting in a denial of service only by manipulating the processed input stream. No user is affected, who followed the recommendation to setup XStream's security framework with a whitelist limited to the minimal required types. XStream 1.4.18 uses no longer a blacklist by default, since it cannot be secured for general purpose.\n\n## Affected\n\n- `xstream < 1.4.18`\n- `debian_linux = 9.0`\n- `debian_linux = 10.0`\n- `debian_linux = 11.0`\n- `fedora = 33`\n- `fedora = 34`\n- `fedora = 35`\n- `snapmanager`\n- `business_activity_monitoring = 12.2.1.4.0`\n- `commerce_guided_search = 11.3.2`\n- `communications_billing_and_revenue_management_elastic_charging_engine = 11.3`\n- `communications_billing_and_revenue_management_elastic_charging_engine = 12.0`\n- `communications_cloud_native_core_automated_test_suite = 1.9.0`\n- `communications_cloud_native_core_binding_support_function = 1.10.0`\n- `communications_cloud_native_core_policy = 1.14.0`\n- `communications_unified_inventory_management = 7.3.4`\n- `communications_unified_inventory_management = 7.3.5`\n- `communications_unified_inventory_management = 7.4.0`\n- `communications_unified_inventory_management = 7.4.1`\n- `communications_unified_inventory_management = 7.4.2`\n- `retail_xstore_point_of_service = 16.0.6`\n- `retail_xstore_point_of_service = 17.0.4`\n- `retail_xstore_point_of_service = 18.0.3`\n- `retail_xstore_point_of_service = 19.0.2`\n- `retail_xstore_point_of_service = 20.0.1`\n- `utilities_framework = 4.2.0.2.0`\n- `utilities_framework = 4.2.0.3.0`\n- `utilities_framework = 4.3.0.1.0`\n- `utilities_framework = 4.3.0.6.0`\n- `utilities_framework = 4.4.0.0.0`\n- `utilities_framework = 4.4.0.2.0`\n- `utilities_framework = 4.4.0.3.0`\n- `utilities_testing_accelerator = 6.0.0.1.1`\n- `webcenter_portal = 12.2.1.3.0`\n- `webcenter_portal = 12.2.1.4.0`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `xstream 1.4.18`","depth":"sunlit","depthScore":37,"depthScoreParts":{"impact":35.8,"likelihood":1.2,"exploitation":0,"ransomware":0},"changes":[]}