Those using Xstream to seralize XML data may be vulnerable to Denial of Service attacks (DOS). If the parser is running on user supplied input, an attacker may supply content that causes the parser to crash by stackoverflow. This effect may support a denial of service attack.
CVSS Details
- CVSS 3.1 Base Score: 6.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon Linux Ami 2 | — | Upgrade xstream-javadocUpgrade xstream | Feb 21, 2024 | Sep 16, 2022 |
| Debian | — | No solution exists | May 15, 2025 | Sep 16, 2022 |
| Freebsd | — | Upgrade keycloak | Jan 17, 2023 | Jan 16, 2023 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Sep 16, 2022 |
| Suse | — | Upgrade xstream-benchmarkUpgrade xstreamUpgrade xstream-parentUpgrade xstream-javadoc | Mar 30, 2023 | Sep 16, 2022 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub