Technology · Maven
com.thoughtworks.xstream:xstream (Maven) vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 37 vulnerabilities in com.thoughtworks.xstream:xstream (Maven): 0 in the last 7 days and 0 in the last 90 days, 1 of them critical and 1 exploited in the wild. The most recent, CVE-2024-47072, was published on 7 November 2024.
- Last 7 days
- 0
- Last 90 days
- 0
- Critical, all time
- 1
- Exploited in the wild
- 1
Latest com.thoughtworks.xstream:xstream (Maven) vulnerabilities
- CVE-2024-47072: XStream is vulnerable to a Denial of Service attack due to stack overflow from a manipulated binary input streamlowCVSS 3.1EPSS 2.0%
- CVE-2022-40151: XStream can cause a Denial of Service by injecting deeply nested objects raising a stack overflowlowCVSS 3.1EPSS 2.2%
- CVE-2022-41966: XStream can cause Denial of Service via stack overflowlowCVSS 3.1EPSS 8.8%
- Duplicate Advisory: Denial of Service due to parser crashinfo
- CVE-2021-43859: Denial of Service by injecting highly recursive collections or maps in XStreamlowCVSS 3.1EPSS 7.9%
- CVE-2021-39139: XStream is vulnerable to an Arbitrary Code Execution attacklowCVSS 3.1EPSS 4.5%
- CVE-2021-39140: XStream can cause a Denial of ServicelowCVSS 3.1EPSS 5.9%
- CVE-2021-39141: XStream is vulnerable to an Arbitrary Code Execution attacklowCVSS 3.1EPSS 16.1%
- CVE-2021-39144: XStream is vulnerable to a Remote Command Execution attackcriticalexploited in the wildCVSS 3.1EPSS 98.1%
- CVE-2021-39145: XStream is vulnerable to an Arbitrary Code Execution attacklowCVSS 3.1EPSS 4.1%
- CVE-2021-39146: XStream is vulnerable to an Arbitrary Code Execution attacklowCVSS 3.1EPSS 14.3%
- CVE-2021-39147: XStream is vulnerable to an Arbitrary Code Execution attacklowCVSS 3.1EPSS 4.7%
- CVE-2021-39148: XStream is vulnerable to an Arbitrary Code Execution attacklowCVSS 3.1EPSS 4.7%
- CVE-2021-39149: XStream is vulnerable to an Arbitrary Code Execution attacklowCVSS 3.1EPSS 4.7%
- CVE-2021-39150: A Server-Side Forgery Request can be activated unmarshalling with XStream to access data streams from an arbitrary URL…lowCVSS 3.1EPSS 3.4%
- CVE-2021-39151: XStream is vulnerable to an Arbitrary Code Execution attacklowCVSS 3.1EPSS 4.7%
- CVE-2021-39152: A Server-Side Forgery Request can be activated unmarshalling with XStream to access data streams from an arbitrary URL…lowCVSS 3.1EPSS 11.4%
- CVE-2021-39153: XStream is vulnerable to an Arbitrary Code Execution attacklowCVSS 3.1EPSS 4.5%
- CVE-2021-39154: XStream is vulnerable to an Arbitrary Code Execution attacklowCVSS 3.1EPSS 4.7%
- CVE-2021-29505: XStream is vulnerable to a Remote Command Execution attacklowCVSS 3.1EPSS 77.2%
- CVE-2021-21351: XStream is vulnerable to an Arbitrary Code Execution attacklowCVSS 3.1EPSS 82.1%
- CVE-2021-21350: XStream is vulnerable to an Arbitrary Code Execution attacklowCVSS 3.1EPSS 15.2%
- CVE-2021-21349: A Server-Side Forgery Request can be activated unmarshalling with XStream to access data streams from an arbitrary URL…lowCVSS 3.1EPSS 46.8%
- CVE-2021-21348: XStream is vulnerable to an attack using Regular Expression for a Denial of Service (ReDos)lowCVSS 3.1EPSS 13.8%
- CVE-2021-21347: XStream is vulnerable to an Arbitrary Code Execution attacklowCVSS 3.1EPSS 14.3%
Most severe com.thoughtworks.xstream:xstream (Maven) vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2021-39144: XStream is vulnerable to a Remote Command Execution attackcriticalexploited in the wildCVSS 3.1EPSS 98.1%
- CVE-2019-10173: Deserialization of Untrusted Data and Code Injection in xstreamlowCVSS 3.1EPSS 95.0%
- CVE-2020-26217: XStream can be used for Remote Code ExecutionlowCVSS 3.1EPSS 85.0%
- CVE-2020-26259: XStream vulnerable to an Arbitrary File Deletion on the local host when unmarshallinglowCVSS 3.1EPSS 82.4%
- CVE-2021-21351: XStream is vulnerable to an Arbitrary Code Execution attacklowCVSS 3.1EPSS 82.1%
- CVE-2020-26258: Server-Side Forgery Request can be activated unmarshalling with XStreamlowCVSS 3.1EPSS 81.8%
- CVE-2021-21341: XStream can cause a Denial of Service.lowCVSS 3.1EPSS 77.8%
- CVE-2021-29505: XStream is vulnerable to a Remote Command Execution attacklowCVSS 3.1EPSS 77.2%
- CVE-2021-21346: XStream is vulnerable to an Arbitrary Code Execution attacklowCVSS 3.1EPSS 76.4%
- CVE-2021-21344: XStream is vulnerable to an Arbitrary Code Execution attacklowCVSS 3.1EPSS 76.0%
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 6 Jul 2026 | 0 | 0 | |
| 13 Jul 2026 | 0 | 0 | |
| 20 Jul 2026 | 0 | 0 | |
| 27 Jul 2026 | 0 | 0 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 0 | 0 | |
| 17 Aug 2026 | 0 | 0 | |
| 24 Aug 2026 | 0 | 0 | |
| 31 Aug 2026 | 0 | 0 | |
| 7 Sep 2026 | 0 | 0 | |
| 14 Sep 2026 | 0 | 0 | |
| 21 Sep 2026 | 0 | 0 | |
| 28 Sep 2026 | 0 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/technologies/com-thoughtworks-xstream-xstream.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "com.thoughtworks.xstream:xstream (Maven) vulnerabilities", https://junglewise.ai/threats/technologies/com-thoughtworks-xstream-xstream, 28 September 2026.