All 34 CVE vulnerabilities found in xstream, with AI-generated Chinese analysis, references, and POCs.
This page details security vulnerabilities associated with xstream, a popular Java library for serializing objects to XML and back, categorized under common weakness types. It aggregates records from various sources to provide a comprehensive view of the security landscape surrounding this widely used technology. The collection spans data from January 2018 through December 2023, covering the period when xstream gained significant market traction and faced increased scrutiny from security researchers and organizations. During this timeframe, numerous vulnerabilities were disclosed, ranging from low-severity configuration issues to critical remote code execution flaws. Users can leverage this aggregation to track xstream’s security advisories and monitor how the vendor responds to different classes of weaknesses. By examining the patterns in reported issues, developers can better understand specific weakness classes that frequently impact this type of serialization library. This resource also allows users to look up xstream’s vulnerability history, helping them assess the maturity of the project’s security practices over time. Understanding the frequency and nature of past incidents enables teams to make informed decisions about upgrading or migrating away from older, unsupported versions. The data is organized to facilitate easy searching by severity, date, and technical impact, ensuring that security professionals can quickly identify relevant risks. This page serves as a central reference point for anyone evaluating the risk profile of xstream within their software supply chain. It aims to provide transparency regarding the history of security defects in the product.
Vendor: xstream
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2020-26258 | Server-Side Forgery Request can be activated unmarshalling with XStream CWE-918 | 6.3 | Medium | 2020-12-16 |
| CVE-2020-26259 | XStream is vulnerable to an Arbitrary File Deletion on the local host when unmarshalling CWE-78 | 6.8 | Medium | 2020-12-16 |
| CVE-2020-26217 | Remote Code Execution in XStream CWE-78 | 8.0 | High | 2020-11-16 |
| CVE-2019-10173 | XStream 代码注入漏洞 CWE-94 | 9.8 | - | 2019-07-23 |
All 34 known CVE vulnerabilities affecting xstream with full Chinese analysis, references, and POCs where available.