Xstream
37 known vulnerabilities
Top Products
XStream serializes Java objects to XML and back again. Versions prior to 1.4.20 may allow a remote attacker to terminate
Those using Woodstox to parse XML data may be vulnerable to Denial of Service attacks (DOS) if DTD support is enabled. I
Those using Xstream to seralize XML data may be vulnerable to Denial of Service attacks (DOS). If the parser is running
XStream is an open source java library to serialize objects to XML and back again. Versions prior to 1.4.19 may allow a
XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allo
XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allo
XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allo
XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allo
XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allo
XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allo
XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allo
XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allo
XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allo
XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allo
XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allo
XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allo
XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allo
XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allo
XStream is software for serializing Java objects to XML and back again. A vulnerability in XStream versions prior to 1.4
XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulne
XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulne
XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulne
XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulne
XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulne
XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulne
XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulne
XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulne
XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulne
XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulne
XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is vulnera
XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.15, is vulnerable to
XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.15, a Server-Side Fo
XStream before version 1.4.14 is vulnerable to Remote Code Execution.The vulnerability may allow a remote attacker to ru
It was found that xstream API version 1.4.10 before 1.4.11 introduced a regression for a previous deserialization flaw.
Xstream API versions up to 1.4.6 and version 1.4.10, if the security framework has not been initialized, may allow a rem
XStream through 1.4.9, when a certain denyTypes workaround is not used, mishandles attempts to create an instance of the
Multiple XML external entity (XXE) vulnerabilities in the (1) Dom4JDriver, (2) DomDriver, (3) JDomDriver, (4) JDom2Drive
Frequently Asked Questions
How many CVEs affect Xstream?
Xstream has 37 CVE records in our database, including 2 critical and 20 high severity vulnerabilities. 1 of these are listed in CISA's Known Exploited Vulnerabilities catalog.
What are the most severe Xstream vulnerabilities?
Xstream has 2 critical severity (CVSS 9.0+) and 20 high severity (CVSS 7.0-8.9) vulnerabilities. 1 vulnerabilities are confirmed as actively exploited in the wild.
How can I scan for Xstream vulnerabilities?
CyberStrike's AI-powered security agents automatically detect vulnerabilities in Xstream products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.
Detect Xstream Vulnerabilities
CyberStrike scans your infrastructure for Xstream vulnerabilities and provides real-time remediation guidance.
Get Started