Disclosure summary
XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a remote attacker to request data from internal resources that are not publicly available only by manipulating the processed input stream. No user is affected, who followed the recommendation to setup XStream's security framework with a whitelist limited to the minimal required types. If you rely on XStream's default blacklist of the Security Framework, you will have to use at least version 1.4.16.
Source-reported weakness categories
CWE-502, CWE-918
Source-specific records & product guidance
Sources retain their own attribution and scoring. Follow the original record to confirm affected versions, fixed releases, and configuration conditions.
NIST National Vulnerability Database · NVD-CVE-2021-21349
Open original source · Updated Oct 07, 2026
Only CPE matches marked vulnerable=true are indexed. AND/OR platform conditions must be checked in the original NVD record.
| Vendor | Product / association | Version / bounds |
|---|---|---|
| netapp | oncommand_insight | - |
| apache | activemq | * {"versionEndExcluding":"5.15.14"} |
| apache | activemq | 5.16.0 |
| apache | activemq | 5.16.1 |
| apache | jmeter | * {"versionEndExcluding":"5.5"} |
| xstream | xstream | * {"versionEndExcluding":"1.4.16"} |
| debian | debian_linux | 9.0 |
| debian | debian_linux | 10.0 |
| debian | debian_linux | 11.0 |
| fedoraproject | fedora | 33 |
| fedoraproject | fedora | 34 |
| fedoraproject | fedora | 35 |
| oracle | banking_enterprise_default_management | 2.10.0 |
| oracle | banking_enterprise_default_management | 2.12.0 |
| oracle | banking_platform | 2.4.0 |
| oracle | banking_platform | 2.7.1 |
| oracle | banking_platform | 2.9.0 |
| oracle | banking_platform | 2.12.0 |
| oracle | banking_virtual_account_management | 14.2.0 |
| oracle | banking_virtual_account_management | 14.3.0 |
| oracle | banking_virtual_account_management | 14.5.0 |
| oracle | business_activity_monitoring | 11.1.1.9.0 |
| oracle | business_activity_monitoring | 12.2.1.3.0 |
| oracle | business_activity_monitoring | 12.2.1.4.0 |
| oracle | communications_billing_and_revenue_management_elastic_charging_engine | 12.0.0.3.0 |
| oracle | communications_policy_management | 12.5.0 |
| oracle | communications_unified_inventory_management | 7.3.2 |
| oracle | communications_unified_inventory_management | 7.3.4 |
| oracle | communications_unified_inventory_management | 7.3.5 |
| oracle | communications_unified_inventory_management | 7.4.0 |
| oracle | communications_unified_inventory_management | 7.4.1 |
| oracle | graalvm | 20.3.4 |
| oracle | graalvm | 21.3.0 |
| oracle | java_se | 7u321 |
| oracle | java_se | 8u311 |
| oracle | retail_xstore_point_of_service | 16.0.6 |
| oracle | retail_xstore_point_of_service | 17.0.4 |
| oracle | retail_xstore_point_of_service | 18.0.3 |
| oracle | retail_xstore_point_of_service | 19.0.2 |
| oracle | webcenter_portal | 11.1.1.9.0 |
| oracle | webcenter_portal | 12.2.1.3.0 |
| oracle | webcenter_portal | 12.2.1.4.0 |
Original records & references
- NIST NVD record
- CVE Program record
- github.com — Third Party Advisory
- lists.apache.org — Issue Tracking, Mailing List, Third Party Advisory
- lists.apache.org — Issue Tracking, Mailing List, Third Party Advisory
- lists.debian.org — Mailing List, Third Party Advisory
- lists.fedoraproject.org — Mailing List, Third Party Advisory
- lists.fedoraproject.org — Mailing List, Third Party Advisory
- lists.fedoraproject.org — Mailing List, Third Party Advisory
- security.netapp.com — Third Party Advisory
- www.debian.org — Mailing List, Third Party Advisory
- www.oracle.com — Third Party Advisory
- www.oracle.com — Patch, Vendor Advisory
- www.oracle.com — Third Party Advisory
- x-stream.github.io — Exploit, Third Party Advisory
- x-stream.github.io — Mitigation, Third Party Advisory
- github.com — Third Party Advisory
- lists.apache.org — Issue Tracking, Mailing List, Third Party Advisory
- lists.apache.org — Issue Tracking, Mailing List, Third Party Advisory
- lists.debian.org — Mailing List, Third Party Advisory
- lists.fedoraproject.org — Mailing List, Third Party Advisory
- lists.fedoraproject.org — Mailing List, Third Party Advisory
- lists.fedoraproject.org — Mailing List, Third Party Advisory
- security.netapp.com — Third Party Advisory
- www.debian.org — Mailing List, Third Party Advisory
- www.oracle.com — Third Party Advisory
- www.oracle.com — Patch, Vendor Advisory
- www.oracle.com — Third Party Advisory
- x-stream.github.io — Exploit, Third Party Advisory
- x-stream.github.io — Mitigation, Third Party Advisory
PUBLISHED 2021-03-22T20:15:13-04:00
MODIFIED 2026-10-07T15:17:24-04:00
INGESTED 2026-10-08T12:30:35-04:00