Disclosure summary
XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a remote attacker to load and execute arbitrary code from a remote host only by manipulating the processed input stream. No user is affected, who followed the recommendation to setup XStream's security framework with a whitelist limited to the minimal required types. If you rely on XStream's default blacklist of the Security Framework, you will have to use at least version 1.4.16.
Source-reported weakness categories
CWE-434, CWE-502, NVD-CWE-noinfo
Source-specific records & product guidance
Sources retain their own attribution and scoring. Follow the original record to confirm affected versions, fixed releases, and configuration conditions.
NIST National Vulnerability Database · NVD-CVE-2021-21344
Open original source · Updated Oct 07, 2026
Only CPE matches marked vulnerable=true are indexed. AND/OR platform conditions must be checked in the original NVD record.
| Vendor | Product / association | Version / bounds |
|---|---|---|
| netapp | oncommand_insight | - |
| apache | activemq | * {"versionEndExcluding":"5.15.14"} |
| apache | activemq | 5.16.0 |
| apache | activemq | 5.16.1 |
| apache | jmeter | * {"versionEndExcluding":"5.5"} |
| xstream | xstream | * {"versionEndExcluding":"1.4.16"} |
| debian | debian_linux | 9.0 |
| debian | debian_linux | 10.0 |
| debian | debian_linux | 11.0 |
| fedoraproject | fedora | 33 |
| fedoraproject | fedora | 34 |
| fedoraproject | fedora | 35 |
| oracle | banking_enterprise_default_management | 2.10.0 |
| oracle | banking_enterprise_default_management | 2.12.0 |
| oracle | banking_platform | 2.4.0 |
| oracle | banking_platform | 2.7.1 |
| oracle | banking_platform | 2.9.0 |
| oracle | banking_platform | 2.12.0 |
| oracle | banking_virtual_account_management | 14.2.0 |
| oracle | banking_virtual_account_management | 14.3.0 |
| oracle | banking_virtual_account_management | 14.5.0 |
| oracle | business_activity_monitoring | 11.1.1.9.0 |
| oracle | business_activity_monitoring | 12.2.1.3.0 |
| oracle | business_activity_monitoring | 12.2.1.4.0 |
| oracle | communications_billing_and_revenue_management_elastic_charging_engine | 12.0.0.3.0 |
| oracle | communications_policy_management | 12.5.0 |
| oracle | communications_unified_inventory_management | 7.3.2 |
| oracle | communications_unified_inventory_management | 7.3.4 |
| oracle | communications_unified_inventory_management | 7.3.5 |
| oracle | communications_unified_inventory_management | 7.4.0 |
| oracle | communications_unified_inventory_management | 7.4.1 |
| oracle | mysql_server | * {"versionStartIncluding":"8.0.0","versionEndIncluding":"8.0.27"} |
| oracle | retail_xstore_point_of_service | 16.0.6 |
| oracle | retail_xstore_point_of_service | 17.0.4 |
| oracle | retail_xstore_point_of_service | 18.0.3 |
| oracle | retail_xstore_point_of_service | 19.0.2 |
| oracle | webcenter_portal | 11.1.1.9.0 |
| oracle | webcenter_portal | 12.2.1.3.0 |
| oracle | webcenter_portal | 12.2.1.4.0 |
Original records & references
- NIST NVD record
- CVE Program record
- github.com — Third Party Advisory
- lists.apache.org — Issue Tracking, Mailing List, Third Party Advisory
- lists.apache.org — Issue Tracking, Mailing List, Third Party Advisory
- lists.debian.org — Mailing List, Third Party Advisory
- lists.fedoraproject.org — Mailing List, Third Party Advisory
- lists.fedoraproject.org — Mailing List, Third Party Advisory
- lists.fedoraproject.org — Mailing List, Third Party Advisory
- security.netapp.com — Third Party Advisory
- www.debian.org — Mailing List, Third Party Advisory
- www.oracle.com — Third Party Advisory
- www.oracle.com — Patch, Vendor Advisory
- www.oracle.com — Third Party Advisory
- x-stream.github.io — Exploit, Third Party Advisory
- x-stream.github.io — Mitigation, Third Party Advisory
- github.com — Third Party Advisory
- lists.apache.org — Issue Tracking, Mailing List, Third Party Advisory
- lists.apache.org — Issue Tracking, Mailing List, Third Party Advisory
- lists.debian.org — Mailing List, Third Party Advisory
- lists.fedoraproject.org — Mailing List, Third Party Advisory
- lists.fedoraproject.org — Mailing List, Third Party Advisory
- lists.fedoraproject.org — Mailing List, Third Party Advisory
- security.netapp.com — Third Party Advisory
- www.debian.org — Mailing List, Third Party Advisory
- www.oracle.com — Third Party Advisory
- www.oracle.com — Patch, Vendor Advisory
- www.oracle.com — Third Party Advisory
- x-stream.github.io — Exploit, Third Party Advisory
- x-stream.github.io — Mitigation, Third Party Advisory
PUBLISHED 2021-03-22T20:15:12-04:00
MODIFIED 2026-10-07T15:17:23-04:00
INGESTED 2026-10-08T12:30:35-04:00