xstream has 4 CVEs on record between 2020 and 2021. The median CVSS is 8.5 (high). The dominant weakness classes are CWE-434 (3) and CWE-502 (3).
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 8.5
- Publish → KEV
- —
- Last 90 days
- 0 prev 0
Worst active — by depth score
CVE-2020-26217High· 8.0XStream before version 1.4.14 is vulnerable to Remote Code Execution.The vulnerability may allow a remote attacker to run arbitrary shell commands only by manipulating the processed input stream73CVE-2021-39154High· 8.5XStream is a simple library to serialize objects to XML and back again48CVE-2021-39149High· 8.5XStream is a simple library to serialize objects to XML and back again48CVE-2021-39145High· 8.5XStream is a simple library to serialize objects to XML and back again48
xstream vulnerabilities
CVEs affecting xstream, newest first. Open any entry for full detail, references, and exploit status.
4 CVEsRSS
CVE-2021-39154High· 8.5XStream is a simple library to serialize objects to XML and back again
XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to load and execute arbitrary code from a remote host only by manipulating the processed input st…
CVE-2021-39149High· 8.5XStream is a simple library to serialize objects to XML and back again
XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to load and execute arbitrary code from a remote host only by manipulating the processed input st…
CVE-2021-39145High· 8.5XStream is a simple library to serialize objects to XML and back again
XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to load and execute arbitrary code from a remote host only by manipulating the processed input st…
CVE-2020-26217High· 8.0PoCXStream before version 1.4.14 is vulnerable to Remote Code Execution.The vulnerability may allow a remote attacker to run arbitrary shell commands only by manipulating the processed input stream
XStream before version 1.4.14 is vulnerable to Remote Code Execution.The vulnerability may allow a remote attacker to run arbitrary shell commands only by manipulating the processed input stream. Only users who rely on blocklists are aff…