{"id":"CVE-2021-39151","title":"XStream is vulnerable to an Arbitrary Code Execution attack","summary":"XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to load and execute arbitrary code from a remote host only by manipulating the processed input st…","severity":"high","cvss":8.5,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H","cvssSource":"cna","cwe":["CWE-434","CWE-502"],"vendor":"x-stream","product":"xstream","affected":["xstream < 1.4.18"],"ssvc":{"exploitation":"none","automatable":"yes","technicalImpact":"total","timestamp":"2026-10-07T20:01:24.822692Z"},"published":"2021-08-23","updated":"2026-10-07","sourceUpdated":"2026-10-07T20:01:37.633Z","source":"CVEORG","sourceUrl":"https://www.cve.org/CVERecord?id=CVE-2021-39151","references":[{"url":"https://github.com/x-stream/xstream/security/advisories/GHSA-hph2-m3g5-xxv4"},{"url":"https://x-stream.github.io/CVE-2021-39151.html"},{"url":"https://lists.debian.org/debian-lts-announce/2021/09/msg00017.html","label":"[debian-lts-announce] 20210929 [SECURITY] [DLA 2769-1] libxstream-java security update"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/22KVR6B5IZP3BGQ3HPWIO2FWWCKT3DHP/","label":"FEDORA-2021-fbad11014a"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/QGXIU3YDPG6OGTDHMBLAFN7BPBERXREB/","label":"FEDORA-2021-d894ca87dc"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/PVPHZA7VW2RRSDCOIPP2W6O5ND254TU7/","label":"FEDORA-2021-5e376c0ed9"},{"url":"https://www.debian.org/security/2021/dsa-5004","label":"DSA-5004"},{"url":"https://www.oracle.com/security-alerts/cpujan2022.html"},{"url":"https://security.netapp.com/advisory/ntap-20210923-0003/"},{"url":"https://www.oracle.com/security-alerts/cpuapr2022.html"},{"url":"https://www.oracle.com/security-alerts/cpujul2022.html"}],"tags":["cve.org"],"epss":0.04735,"epssPercentile":0.91603,"ingestedAt":"2026-10-07T20:46:47.002Z","slug":"CVE-2021-39151","body":"## Overview\n\nXStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to load and execute arbitrary code from a remote host only by manipulating the processed input stream. No user is affected, who followed the recommendation to setup XStream's security framework with a whitelist limited to the minimal required types. XStream 1.4.18 uses no longer a blacklist by default, since it cannot be secured for general purpose.\n\n## Affected\n\n- `xstream < 1.4.18`\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"twilight","depthScore":48,"depthScoreParts":{"impact":46.8,"likelihood":0.9,"exploitation":0,"ransomware":0},"changes":[]}