{"id":"CVE-2021-39150","title":"XStream is a simple library to serialize objects to XML and back again","summary":"XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to request data from internal resources that are not publicly available only by manipulating the …","severity":"high","cvss":8.5,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H","cwe":["CWE-502","CWE-918"],"vendor":"xstream","product":"xstream","affected":["xstream < 1.4.18","fedora = 33","fedora = 34","fedora = 35","debian_linux = 9.0","debian_linux = 10.0","debian_linux = 11.0","snapmanager","business_activity_monitoring = 12.2.1.4.0","commerce_guided_search = 11.3.2","communications_billing_and_revenue_management_elastic_charging_engine = 11.3","communications_billing_and_revenue_management_elastic_charging_engine = 12.0","communications_cloud_native_core_automated_test_suite = 1.9.0","communications_cloud_native_core_binding_support_function = 1.10.0","communications_cloud_native_core_policy = 1.14.0","communications_unified_inventory_management = 7.3.4","communications_unified_inventory_management = 7.3.5","communications_unified_inventory_management = 7.4.0","communications_unified_inventory_management = 7.4.1","communications_unified_inventory_management = 7.4.2","retail_xstore_point_of_service = 16.0.6","retail_xstore_point_of_service = 17.0.4","retail_xstore_point_of_service = 18.0.3","retail_xstore_point_of_service = 19.0.2","retail_xstore_point_of_service = 20.0.1","utilities_framework = 4.2.0.2.0","utilities_framework = 4.2.0.3.0","utilities_framework = 4.3.0.1.0","utilities_framework = 4.3.0.6.0","utilities_framework = 4.4.0.0.0","utilities_framework = 4.4.0.2.0","utilities_framework = 4.4.0.3.0","utilities_testing_accelerator = 6.0.0.1.1","webcenter_portal = 12.2.1.3.0","webcenter_portal = 12.2.1.4.0"],"patched":["xstream 1.4.18"],"published":"2021-08-23","updated":"2026-10-07","sourceUpdated":"2026-10-07T21:17:04.717","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2021-39150","references":[{"url":"https://github.com/x-stream/xstream/security/advisories/GHSA-cxfm-5m4g-x7xp","label":"security-advisories@github.com"},{"url":"https://lists.debian.org/debian-lts-announce/2021/09/msg00017.html","label":"security-advisories@github.com"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/22KVR6B5IZP3BGQ3HPWIO2FWWCKT3DHP/","label":"security-advisories@github.com"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/PVPHZA7VW2RRSDCOIPP2W6O5ND254TU7/","label":"security-advisories@github.com"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/QGXIU3YDPG6OGTDHMBLAFN7BPBERXREB/","label":"security-advisories@github.com"},{"url":"https://security.netapp.com/advisory/ntap-20210923-0003/","label":"security-advisories@github.com"},{"url":"https://www.debian.org/security/2021/dsa-5004","label":"security-advisories@github.com"},{"url":"https://www.oracle.com/security-alerts/cpuapr2022.html","label":"security-advisories@github.com"},{"url":"https://www.oracle.com/security-alerts/cpujan2022.html","label":"security-advisories@github.com"},{"url":"https://www.oracle.com/security-alerts/cpujul2022.html","label":"security-advisories@github.com"},{"url":"https://x-stream.github.io/CVE-2021-39150.html","label":"security-advisories@github.com"},{"url":"https://github.com/x-stream/xstream/security/advisories/GHSA-cxfm-5m4g-x7xp","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.debian.org/debian-lts-announce/2021/09/msg00017.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/22KVR6B5IZP3BGQ3HPWIO2FWWCKT3DHP/","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/PVPHZA7VW2RRSDCOIPP2W6O5ND254TU7/","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/QGXIU3YDPG6OGTDHMBLAFN7BPBERXREB/","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://security.netapp.com/advisory/ntap-20210923-0003/","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.debian.org/security/2021/dsa-5004","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.oracle.com/security-alerts/cpuapr2022.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.oracle.com/security-alerts/cpujan2022.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.oracle.com/security-alerts/cpujul2022.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://x-stream.github.io/CVE-2021-39150.html","label":"af854a3a-2127-422b-91ae-364da2661108"}],"tags":["nvd","cve.org"],"epss":0.03437,"epssPercentile":0.88629,"ssvc":{"exploitation":"none","automatable":"yes","technicalImpact":"total","timestamp":"2026-10-07T19:59:41.571622Z"},"ingestedAt":"2026-10-07T20:46:47.003Z","slug":"CVE-2021-39150","body":"## Overview\n\nXStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to request data from internal resources that are not publicly available only by manipulating the processed input stream with a Java runtime version 14 to 8. No user is affected, who followed the recommendation to setup XStream's security framework with a whitelist limited to the minimal required types. If you rely on XStream's default blacklist of the [Security Framework](https://x-stream.github.io/security.html#framework), you will have to use at least version 1.4.18.\n\n## Affected\n\n- `xstream < 1.4.18`\n- `fedora = 33`\n- `fedora = 34`\n- `fedora = 35`\n- `debian_linux = 9.0`\n- `debian_linux = 10.0`\n- `debian_linux = 11.0`\n- `snapmanager`\n- `business_activity_monitoring = 12.2.1.4.0`\n- `commerce_guided_search = 11.3.2`\n- `communications_billing_and_revenue_management_elastic_charging_engine = 11.3`\n- `communications_billing_and_revenue_management_elastic_charging_engine = 12.0`\n- `communications_cloud_native_core_automated_test_suite = 1.9.0`\n- `communications_cloud_native_core_binding_support_function = 1.10.0`\n- `communications_cloud_native_core_policy = 1.14.0`\n- `communications_unified_inventory_management = 7.3.4`\n- `communications_unified_inventory_management = 7.3.5`\n- `communications_unified_inventory_management = 7.4.0`\n- `communications_unified_inventory_management = 7.4.1`\n- `communications_unified_inventory_management = 7.4.2`\n- `retail_xstore_point_of_service = 16.0.6`\n- `retail_xstore_point_of_service = 17.0.4`\n- `retail_xstore_point_of_service = 18.0.3`\n- `retail_xstore_point_of_service = 19.0.2`\n- `retail_xstore_point_of_service = 20.0.1`\n- `utilities_framework = 4.2.0.2.0`\n- `utilities_framework = 4.2.0.3.0`\n- `utilities_framework = 4.3.0.1.0`\n- `utilities_framework = 4.3.0.6.0`\n- `utilities_framework = 4.4.0.0.0`\n- `utilities_framework = 4.4.0.2.0`\n- `utilities_framework = 4.4.0.3.0`\n- `utilities_testing_accelerator = 6.0.0.1.1`\n- `webcenter_portal = 12.2.1.3.0`\n- `webcenter_portal = 12.2.1.4.0`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `xstream 1.4.18`","depth":"twilight","depthScore":47,"depthScoreParts":{"impact":46.8,"likelihood":0.7,"exploitation":0,"ransomware":0},"changes":[]}