{"schema_version":1,"title":"com.thoughtworks.xstream:xstream (Maven) vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 37 vulnerabilities in com.thoughtworks.xstream:xstream (Maven): 0 in the last 7 days and 0 in the last 90 days, 1 of them critical and 1 exploited in the wild. The most recent, CVE-2024-47072, was published on 7 November 2024.","url":"https://junglewise.ai/threats/technologies/com-thoughtworks-xstream-xstream","json_url":"https://junglewise.ai/threats/technologies/com-thoughtworks-xstream-xstream.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/technologies/com-thoughtworks-xstream-xstream","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"technology","counts":{"high":0,"all_time":37,"critical":1,"exploited":1,"last_7_days":0,"last_30_days":0,"last_90_days":0,"last_365_days":0},"latest":[{"cve":"CVE-2024-47072","cvss":3.1,"epss":0.02,"slug":"cve-2024-47072-xstream-is-vulnerable-to-a-denial-of-service-attack-due-to-stack","title":"XStream is vulnerable to a Denial of Service attack due to stack overflow from a manipulated binary input stream","severity":"low","exploited":false,"published_at":"2024-11-07T21:51:17+00:00","url":"https://junglewise.ai/threats/cve-2024-47072-xstream-is-vulnerable-to-a-denial-of-service-attack-due-to-stack"},{"cve":"CVE-2022-40151","cvss":3.1,"epss":0.0222,"slug":"cve-2022-40151-xstream-can-cause-a-denial-of-service-by-injecting-deeply-nested","title":"XStream can cause a Denial of Service by injecting deeply nested objects raising a stack overflow","severity":"low","exploited":false,"published_at":"2022-12-30T16:58:39+00:00","url":"https://junglewise.ai/threats/cve-2022-40151-xstream-can-cause-a-denial-of-service-by-injecting-deeply-nested"},{"cve":"CVE-2022-41966","cvss":3.1,"epss":0.0876,"slug":"cve-2022-41966-xstream-can-cause-denial-of-service-via-stack-overflow","title":"XStream can cause Denial of Service via stack overflow","severity":"low","exploited":false,"published_at":"2022-12-29T01:48:08+00:00","url":"https://junglewise.ai/threats/cve-2022-41966-xstream-can-cause-denial-of-service-via-stack-overflow"},{"slug":"duplicate-advisory-denial-of-service-due-to-parser-crash-92e16523","title":"Duplicate Advisory: Denial of Service due to parser crash","severity":"info","exploited":false,"published_at":"2022-09-17T00:00:41+00:00","url":"https://junglewise.ai/threats/duplicate-advisory-denial-of-service-due-to-parser-crash-92e16523"},{"cve":"CVE-2021-43859","cvss":3.1,"epss":0.0793,"slug":"cve-2021-43859-denial-of-service-by-injecting-highly-recursive-collections-or","title":"Denial of Service by injecting highly recursive collections or maps in XStream","severity":"low","exploited":false,"published_at":"2022-02-01T00:48:15+00:00","url":"https://junglewise.ai/threats/cve-2021-43859-denial-of-service-by-injecting-highly-recursive-collections-or"},{"cve":"CVE-2021-39139","cvss":3.1,"epss":0.0454,"slug":"cve-2021-39139-xstream-is-vulnerable-to-an-arbitrary-code-execution-attack","title":"XStream is vulnerable to an Arbitrary Code Execution attack","severity":"low","exploited":false,"published_at":"2021-08-25T14:48:47+00:00","url":"https://junglewise.ai/threats/cve-2021-39139-xstream-is-vulnerable-to-an-arbitrary-code-execution-attack"},{"cve":"CVE-2021-39140","cvss":3.1,"epss":0.0592,"slug":"cve-2021-39140-xstream-can-cause-a-denial-of-service","title":"XStream can cause a Denial of Service","severity":"low","exploited":false,"published_at":"2021-08-25T14:48:39+00:00","url":"https://junglewise.ai/threats/cve-2021-39140-xstream-can-cause-a-denial-of-service"},{"cve":"CVE-2021-39141","cvss":3.1,"epss":0.1612,"slug":"cve-2021-39141-xstream-is-vulnerable-to-an-arbitrary-code-execution-attack","title":"XStream is vulnerable to an Arbitrary Code Execution attack","severity":"low","exploited":false,"published_at":"2021-08-25T14:48:31+00:00","url":"https://junglewise.ai/threats/cve-2021-39141-xstream-is-vulnerable-to-an-arbitrary-code-execution-attack"},{"cve":"CVE-2021-39144","cvss":3.1,"epss":0.9812,"slug":"cve-2021-39144-xstream-remote-code-execution-vulnerability","title":"XStream is vulnerable to a Remote Command Execution attack","severity":"critical","exploited":true,"published_at":"2021-08-25T14:48:19+00:00","url":"https://junglewise.ai/threats/cve-2021-39144-xstream-remote-code-execution-vulnerability"},{"cve":"CVE-2021-39145","cvss":3.1,"epss":0.0407,"slug":"cve-2021-39145-xstream-is-vulnerable-to-an-arbitrary-code-execution-attack","title":"XStream is vulnerable to an Arbitrary Code Execution attack","severity":"low","exploited":false,"published_at":"2021-08-25T14:48:12+00:00","url":"https://junglewise.ai/threats/cve-2021-39145-xstream-is-vulnerable-to-an-arbitrary-code-execution-attack"},{"cve":"CVE-2021-39146","cvss":3.1,"epss":0.143,"slug":"cve-2021-39146-xstream-is-vulnerable-to-an-arbitrary-code-execution-attack","title":"XStream is vulnerable to an Arbitrary Code Execution attack","severity":"low","exploited":false,"published_at":"2021-08-25T14:47:57+00:00","url":"https://junglewise.ai/threats/cve-2021-39146-xstream-is-vulnerable-to-an-arbitrary-code-execution-attack"},{"cve":"CVE-2021-39147","cvss":3.1,"epss":0.0474,"slug":"cve-2021-39147-xstream-is-vulnerable-to-an-arbitrary-code-execution-attack","title":"XStream is vulnerable to an Arbitrary Code Execution attack","severity":"low","exploited":false,"published_at":"2021-08-25T14:47:46+00:00","url":"https://junglewise.ai/threats/cve-2021-39147-xstream-is-vulnerable-to-an-arbitrary-code-execution-attack"},{"cve":"CVE-2021-39148","cvss":3.1,"epss":0.0474,"slug":"cve-2021-39148-xstream-is-vulnerable-to-an-arbitrary-code-execution-attack","title":"XStream is vulnerable to an Arbitrary Code Execution attack","severity":"low","exploited":false,"published_at":"2021-08-25T14:47:38+00:00","url":"https://junglewise.ai/threats/cve-2021-39148-xstream-is-vulnerable-to-an-arbitrary-code-execution-attack"},{"cve":"CVE-2021-39149","cvss":3.1,"epss":0.0474,"slug":"cve-2021-39149-xstream-is-vulnerable-to-an-arbitrary-code-execution-attack","title":"XStream is vulnerable to an Arbitrary Code Execution attack","severity":"low","exploited":false,"published_at":"2021-08-25T14:47:28+00:00","url":"https://junglewise.ai/threats/cve-2021-39149-xstream-is-vulnerable-to-an-arbitrary-code-execution-attack"},{"cve":"CVE-2021-39150","cvss":3.1,"epss":0.0344,"slug":"cve-2021-39150-a-server-side-forgery-request-can-be-activated-unmarshalling-with","title":"A Server-Side Forgery Request can be activated unmarshalling with XStream to access data streams from an arbitrary URL referencing a resourc","severity":"low","exploited":false,"published_at":"2021-08-25T14:47:19+00:00","url":"https://junglewise.ai/threats/cve-2021-39150-a-server-side-forgery-request-can-be-activated-unmarshalling-with"},{"cve":"CVE-2021-39151","cvss":3.1,"epss":0.0474,"slug":"cve-2021-39151-xstream-is-vulnerable-to-an-arbitrary-code-execution-attack","title":"XStream is vulnerable to an Arbitrary Code Execution attack","severity":"low","exploited":false,"published_at":"2021-08-25T14:47:09+00:00","url":"https://junglewise.ai/threats/cve-2021-39151-xstream-is-vulnerable-to-an-arbitrary-code-execution-attack"},{"cve":"CVE-2021-39152","cvss":3.1,"epss":0.1138,"slug":"cve-2021-39152-a-server-side-forgery-request-can-be-activated-unmarshalling-with","title":"A Server-Side Forgery Request can be activated unmarshalling with XStream to access data streams from an arbitrary URL referencing a resourc","severity":"low","exploited":false,"published_at":"2021-08-25T14:46:59+00:00","url":"https://junglewise.ai/threats/cve-2021-39152-a-server-side-forgery-request-can-be-activated-unmarshalling-with"},{"cve":"CVE-2021-39153","cvss":3.1,"epss":0.0446,"slug":"cve-2021-39153-xstream-is-vulnerable-to-an-arbitrary-code-execution-attack","title":"XStream is vulnerable to an Arbitrary Code Execution attack","severity":"low","exploited":false,"published_at":"2021-08-25T14:46:49+00:00","url":"https://junglewise.ai/threats/cve-2021-39153-xstream-is-vulnerable-to-an-arbitrary-code-execution-attack"},{"cve":"CVE-2021-39154","cvss":3.1,"epss":0.0474,"slug":"cve-2021-39154-xstream-is-vulnerable-to-an-arbitrary-code-execution-attack","title":"XStream is vulnerable to an Arbitrary Code Execution attack","severity":"low","exploited":false,"published_at":"2021-08-25T14:46:38+00:00","url":"https://junglewise.ai/threats/cve-2021-39154-xstream-is-vulnerable-to-an-arbitrary-code-execution-attack"},{"cve":"CVE-2021-29505","cvss":3.1,"epss":0.7723,"slug":"cve-2021-29505-xstream-is-vulnerable-to-a-remote-command-execution-attack","title":"XStream is vulnerable to a Remote Command Execution attack","severity":"low","exploited":false,"published_at":"2021-05-18T18:36:27+00:00","url":"https://junglewise.ai/threats/cve-2021-29505-xstream-is-vulnerable-to-a-remote-command-execution-attack"},{"cve":"CVE-2021-21351","cvss":3.1,"epss":0.8214,"slug":"cve-2021-21351-xstream-is-vulnerable-to-an-arbitrary-code-execution-attack","title":"XStream is vulnerable to an Arbitrary Code Execution attack","severity":"low","exploited":false,"published_at":"2021-03-22T23:29:37+00:00","url":"https://junglewise.ai/threats/cve-2021-21351-xstream-is-vulnerable-to-an-arbitrary-code-execution-attack"},{"cve":"CVE-2021-21350","cvss":3.1,"epss":0.1523,"slug":"cve-2021-21350-xstream-is-vulnerable-to-an-arbitrary-code-execution-attack","title":"XStream is vulnerable to an Arbitrary Code Execution attack","severity":"low","exploited":false,"published_at":"2021-03-22T23:29:28+00:00","url":"https://junglewise.ai/threats/cve-2021-21350-xstream-is-vulnerable-to-an-arbitrary-code-execution-attack"},{"cve":"CVE-2021-21349","cvss":3.1,"epss":0.4683,"slug":"cve-2021-21349-a-server-side-forgery-request-can-be-activated-unmarshalling-with","title":"A Server-Side Forgery Request can be activated unmarshalling with XStream to access data streams from an arbitrary URL referencing a resourc","severity":"low","exploited":false,"published_at":"2021-03-22T23:29:19+00:00","url":"https://junglewise.ai/threats/cve-2021-21349-a-server-side-forgery-request-can-be-activated-unmarshalling-with"},{"cve":"CVE-2021-21348","cvss":3.1,"epss":0.1383,"slug":"cve-2021-21348-xstream-is-vulnerable-to-an-attack-using-regular-expression-for-a","title":"XStream is vulnerable to an attack using Regular Expression for a Denial of Service (ReDos)","severity":"low","exploited":false,"published_at":"2021-03-22T23:29:09+00:00","url":"https://junglewise.ai/threats/cve-2021-21348-xstream-is-vulnerable-to-an-attack-using-regular-expression-for-a"},{"cve":"CVE-2021-21347","cvss":3.1,"epss":0.143,"slug":"cve-2021-21347-xstream-is-vulnerable-to-an-arbitrary-code-execution-attack","title":"XStream is vulnerable to an Arbitrary Code Execution attack","severity":"low","exploited":false,"published_at":"2021-03-22T23:29:00+00:00","url":"https://junglewise.ai/threats/cve-2021-21347-xstream-is-vulnerable-to-an-arbitrary-code-execution-attack"}],"weekly":[{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-28","critical":0,"exploited":0,"vulnerabilities":0}],"related":[{"name":"com.liferay.portal:release.portal.bom (Maven)","slug":"com-liferay-portal-release-portal-bom","vulnerabilities":92,"url":"https://junglewise.ai/threats/technologies/com-liferay-portal-release-portal-bom"},{"name":"org.keycloak:keycloak-services (Maven)","slug":"org-keycloak-keycloak-services","vulnerabilities":76,"url":"https://junglewise.ai/threats/technologies/org-keycloak-keycloak-services"},{"name":"org.keycloak:keycloak-core (Maven)","slug":"org-keycloak-keycloak-core","vulnerabilities":56,"url":"https://junglewise.ai/threats/technologies/org-keycloak-keycloak-core"},{"name":"org.apache.struts:struts2-core (Maven)","slug":"org-apache-struts-struts2-core","vulnerabilities":40,"url":"https://junglewise.ai/threats/technologies/org-apache-struts-struts2-core"},{"name":"net.mingsoft:ms-mcms (Maven)","slug":"net-mingsoft-ms-mcms","vulnerabilities":39,"url":"https://junglewise.ai/threats/technologies/net-mingsoft-ms-mcms"},{"name":"com.jfinal:jfinal (Maven)","slug":"com-jfinal-jfinal","vulnerabilities":36,"url":"https://junglewise.ai/threats/technologies/com-jfinal-jfinal"},{"name":"org.jenkins-ci.plugins:script-security (Maven)","slug":"org-jenkins-ci-plugins-script-security","vulnerabilities":36,"url":"https://junglewise.ai/threats/technologies/org-jenkins-ci-plugins-script-security"},{"name":"org.apache.tomcat:tomcat (Maven)","slug":"org-apache-tomcat-tomcat","vulnerabilities":35,"url":"https://junglewise.ai/threats/technologies/org-apache-tomcat-tomcat"},{"name":"com.liferay.portal:release.dxp.bom (Maven)","slug":"com-liferay-portal-release-dxp-bom","vulnerabilities":34,"url":"https://junglewise.ai/threats/technologies/com-liferay-portal-release-dxp-bom"},{"name":"org.opencms:opencms-core (Maven)","slug":"org-opencms-opencms-core","vulnerabilities":31,"url":"https://junglewise.ai/threats/technologies/org-opencms-opencms-core"},{"name":"org.keycloak:keycloak-parent (Maven)","slug":"org-keycloak-keycloak-parent","vulnerabilities":26,"url":"https://junglewise.ai/threats/technologies/org-keycloak-keycloak-parent"},{"name":"com.fasterxml.jackson.core:jackson-databind (Maven)","slug":"com-fasterxml-jackson-core-jackson-databind","vulnerabilities":25,"url":"https://junglewise.ai/threats/technologies/com-fasterxml-jackson-core-jackson-databind"}],"technology":{"hub":true,"name":"com.thoughtworks.xstream:xstream (Maven)","slug":"com-thoughtworks-xstream-xstream","vendor":{"name":"Maven","slug":"maven","url":"https://junglewise.ai/threats/vendors/maven"},"aliases":[],"url":"https://junglewise.ai/threats/technologies/com-thoughtworks-xstream-xstream"},"most_severe":[{"cve":"CVE-2021-39144","cvss":3.1,"epss":0.9812,"slug":"cve-2021-39144-xstream-remote-code-execution-vulnerability","title":"XStream is vulnerable to a Remote Command Execution attack","severity":"critical","exploited":true,"published_at":"2021-08-25T14:48:19+00:00","url":"https://junglewise.ai/threats/cve-2021-39144-xstream-remote-code-execution-vulnerability"},{"cve":"CVE-2019-10173","cvss":3.1,"epss":0.9504,"slug":"cve-2019-10173-deserialization-of-untrusted-data-and-code-injection-in-xstream","title":"Deserialization of Untrusted Data and Code Injection in xstream","severity":"low","exploited":false,"published_at":"2019-07-26T16:09:47+00:00","url":"https://junglewise.ai/threats/cve-2019-10173-deserialization-of-untrusted-data-and-code-injection-in-xstream"},{"cve":"CVE-2020-26217","cvss":3.1,"epss":0.85,"slug":"cve-2020-26217-xstream-can-be-used-for-remote-code-execution","title":"XStream can be used for Remote Code Execution","severity":"low","exploited":false,"published_at":"2020-11-16T20:07:59+00:00","url":"https://junglewise.ai/threats/cve-2020-26217-xstream-can-be-used-for-remote-code-execution"},{"cve":"CVE-2020-26259","cvss":3.1,"epss":0.8239,"slug":"cve-2020-26259-xstream-vulnerable-to-an-arbitrary-file-deletion-on-the-local","title":"XStream vulnerable to an Arbitrary File Deletion on the local host when unmarshalling","severity":"low","exploited":false,"published_at":"2020-12-21T16:28:26+00:00","url":"https://junglewise.ai/threats/cve-2020-26259-xstream-vulnerable-to-an-arbitrary-file-deletion-on-the-local"},{"cve":"CVE-2021-21351","cvss":3.1,"epss":0.8214,"slug":"cve-2021-21351-xstream-is-vulnerable-to-an-arbitrary-code-execution-attack","title":"XStream is vulnerable to an Arbitrary Code Execution attack","severity":"low","exploited":false,"published_at":"2021-03-22T23:29:37+00:00","url":"https://junglewise.ai/threats/cve-2021-21351-xstream-is-vulnerable-to-an-arbitrary-code-execution-attack"},{"cve":"CVE-2020-26258","cvss":3.1,"epss":0.8182,"slug":"cve-2020-26258-server-side-forgery-request-can-be-activated-unmarshalling-with","title":"Server-Side Forgery Request can be activated unmarshalling with XStream","severity":"low","exploited":false,"published_at":"2020-12-21T16:28:42+00:00","url":"https://junglewise.ai/threats/cve-2020-26258-server-side-forgery-request-can-be-activated-unmarshalling-with"},{"cve":"CVE-2021-21341","cvss":3.1,"epss":0.778,"slug":"cve-2021-21341-xstream-can-cause-a-denial-of-service","title":"XStream can cause a Denial of Service.","severity":"low","exploited":false,"published_at":"2021-03-22T23:27:51+00:00","url":"https://junglewise.ai/threats/cve-2021-21341-xstream-can-cause-a-denial-of-service"},{"cve":"CVE-2021-29505","cvss":3.1,"epss":0.7723,"slug":"cve-2021-29505-xstream-is-vulnerable-to-a-remote-command-execution-attack","title":"XStream is vulnerable to a Remote Command Execution attack","severity":"low","exploited":false,"published_at":"2021-05-18T18:36:27+00:00","url":"https://junglewise.ai/threats/cve-2021-29505-xstream-is-vulnerable-to-a-remote-command-execution-attack"},{"cve":"CVE-2021-21346","cvss":3.1,"epss":0.7637,"slug":"cve-2021-21346-xstream-is-vulnerable-to-an-arbitrary-code-execution-attack","title":"XStream is vulnerable to an Arbitrary Code Execution attack","severity":"low","exploited":false,"published_at":"2021-03-22T23:28:49+00:00","url":"https://junglewise.ai/threats/cve-2021-21346-xstream-is-vulnerable-to-an-arbitrary-code-execution-attack"},{"cve":"CVE-2021-21344","cvss":3.1,"epss":0.7598,"slug":"cve-2021-21344-xstream-is-vulnerable-to-an-arbitrary-code-execution-attack","title":"XStream is vulnerable to an Arbitrary Code Execution attack","severity":"low","exploited":false,"published_at":"2021-03-22T23:28:23+00:00","url":"https://junglewise.ai/threats/cve-2021-21344-xstream-is-vulnerable-to-an-arbitrary-code-execution-attack"}],"generated_at":"2026-09-28T03:07:00.154823+00:00"}