Junglewise Threat Intelligence

CVE-2022-40151: XStream can cause a Denial of Service by injecting deeply nested objects raising a stack overflow

CVE-2022-40151 · Severity: low · CVSS 3.1 · Published 2022-12-30

Technologies: com.thoughtworks.xstream:xstream (Maven). Vendors: Maven.

Executive brief

XStream can cause a Denial of Service by injecting deeply nested objects raising a stack overflow

Affected products

  • Maven com.thoughtworks.xstream:xstream

Related threats