HIGH 7.5 Maven

Denial of service in XStream

GHSA-7hwc-46rm-65jh · CVE-2017-7957

Published · Modified

AI SAST

Find this class of vulnerability in your own code

Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.

Description

XStream through 1.4.9, when a certain denyTypes workaround is not used, mishandles attempts to create an instance of the primitive type 'void' during unmarshalling, leading to a remote application crash, as demonstrated by an xstream.fromXML("") call.

Ready to move

Start Securing

Free, no credit card | First findings in minutes