CVE-2020-26258Medium· 6.3▾ TwilightPoC availableXStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.15, a Server-Side Forgery Request vulnerability can be activated when unmarshalling. The vulnerability may allow a remote attacker to req…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 34.7 · likelihood 16.4 · exploitation 12
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Public exploit / PoC code seen in 2 sources. Availability, not in-the-wild use.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
82%
2 GitHub repos · Nuclei ×1 (last check)
XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.15, a Server-Side Forgery Request vulnerability can be activated when unmarshalling. The vulnerability may allow a remote attacker to request data from internal resources that are not publicly available only by manipulating the processed input stream. If you rely on XStream's default blacklist of the Security Framework, you will have to use at least version 1.4.15. The reported vulnerability does not exist if running Java 15 or higher. No user is affected who followed the recommendation to setup XStream's Security Framework with a whitelist! Anyone relying on XStream's default blacklist can immediately switch to a whilelist for the allowed types to avoid the vulnerability. Users of XStream 1.4.14 or below who still want to use XStream default blacklist can use a workaround described in more detailed in the referenced advisories.
struts < 6.0.0xstream < 1.4.15debian_linux = 9.0debian_linux = 10.0fedora = 33fedora = 34fedora = 35Upgrade past the affected range:
struts 6.0.0xstream 1.4.15Connected by shared product, vendor, weakness, or advisory.
CVE-2020-26259Medium· 6.8XStream is a Java library to serialize objects to XML and back again
CVE-2021-39152High· 8.5XStream is a simple library to serialize objects to XML and back again
CVE-2021-21349Medium· 6.1XStream is a Java library to serialize objects to XML and back again
CVE-2021-39150High· 8.5XStream is a simple library to serialize objects to XML and back again
CVE-2021-21342Medium· 5.3XStream is a Java library to serialize objects to XML and back again
CVE-2025-68616High· 7.5WeasyPrint helps web developers to create PDF documents