Dependency scanning
Check whether com.thoughtworks.xstream:xstream is in your codebase
Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.
Vulnerabilities
CVE-2021-39148
XStream is vulnerable to an Arbitrary Code Execution attack
CVE-2021-21344
XStream is vulnerable to an Arbitrary Code Execution attack
CVE-2021-21349
A Server-Side Forgery Request can be activated unmarshalling with XStream to access data streams from an arbitrary URL referencing a resource in an intranet or the local host
CVE-2021-21343
XStream is vulnerable to an Arbitrary File Deletion on the local host when unmarshalling as long as the executing process has sufficient rights
CVE-2021-21341
XStream can cause a Denial of Service.
CVE-2021-21346
XStream is vulnerable to an Arbitrary Code Execution attack
CVE-2021-39141
XStream is vulnerable to an Arbitrary Code Execution attack
CVE-2021-43859
Denial of Service by injecting highly recursive collections or maps in XStream
CVE-2021-39150
A Server-Side Forgery Request can be activated unmarshalling with XStream to access data streams from an arbitrary URL referencing a resource in an intranet or the local host
CVE-2021-21347
XStream is vulnerable to an Arbitrary Code Execution attack
CVE-2021-39146
XStream is vulnerable to an Arbitrary Code Execution attack
CVE-2021-39147
XStream is vulnerable to an Arbitrary Code Execution attack
CVE-2021-39145
XStream is vulnerable to an Arbitrary Code Execution attack
CVE-2021-21342
A Server-Side Forgery Request can be activated unmarshalling with XStream to access data streams from an arbitrary URL referencing a resource in an intranet or the local host
CVE-2021-21345
XStream is vulnerable to a Remote Command Execution attack
CVE-2021-29505
XStream is vulnerable to a Remote Command Execution attack
CVE-2021-39151
XStream is vulnerable to an Arbitrary Code Execution attack
CVE-2021-39153
XStream is vulnerable to an Arbitrary Code Execution attack
CVE-2021-39139
XStream is vulnerable to an Arbitrary Code Execution attack
CVE-2021-39149
XStream is vulnerable to an Arbitrary Code Execution attack
CVE-2021-39154
XStream is vulnerable to an Arbitrary Code Execution attack
CVE-2021-21350
XStream is vulnerable to an Arbitrary Code Execution attack
CVE-2021-21351
XStream is vulnerable to an Arbitrary Code Execution attack
CVE-2021-39140
XStream can cause a Denial of Service
CVE-2021-39144
XStream is vulnerable to a Remote Command Execution attack
CVE-2021-21348
XStream is vulnerable to an attack using Regular Expression for a Denial of Service (ReDos)
CVE-2021-39152
A Server-Side Forgery Request can be activated unmarshalling with XStream to access data streams from an arbitrary URL referencing a resource in an intranet or the local host
CVE-2020-26217
XStream can be used for Remote Code Execution
CVE-2020-26259
XStream vulnerable to an Arbitrary File Deletion on the local host when unmarshalling
CVE-2020-26258
Server-Side Forgery Request can be activated unmarshalling with XStream
CVE-2019-10173
Deserialization of Untrusted Data and Code Injection in xstream
CVE-2024-47072
XStream is vulnerable to a Denial of Service attack due to stack overflow from a manipulated binary input stream
CVE-2017-7957
Denial of service in XStream
CVE-2016-3674
XML External Entity Injection in XStream
GHSA-3mq5-fq9h-gj7j
Duplicate Advisory: Denial of Service due to parser crash
CVE-2013-7285
Command Injection in Xstream
CVE-2022-41966
XStream can cause Denial of Service via stack overflow
CVE-2022-40151
XStream can cause a Denial of Service by injecting deeply nested objects raising a stack overflow
Browse more Maven advisories
Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →
Ready to move
Start Securing
Free, no credit card | First findings in minutes