CVE-2021-39144
CWE-94
96.0
RPSRPS range: 0–105; KEV-listed vulnerabilities can receive an exploitation amplifier.
Description
XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker has sufficient rights to execute commands of the host only by manipulating the processed input stream. No user is affected, who followed the recommendation to setup XStream's security framework with a whitelist limited to the minimal required types. XStream 1.4.18 uses no longer a blacklist by default, since it cannot be secured for general purpose.
Source: NVD
Signals
- CVSS
- 8.5
- High · v3.1
- EPSS
- 98.12%
- Probability of exploitation in the next 30 days (FIRST)
- CISA KEV
- In CISA KEV since Mar 2023
- Fix commit
- No known fix commit
- Sources: MoreFixes, FreshFixes
- Weakness
- CWE-94
- CWE-94, CWE-306
- Published
- 23 Aug 2021
- Last modified 24 Oct 2025
How to read these signals: RPS · EPSS · CISA KEV · Data sources
Get this score from the API
curl -H "Authorization: Bearer dsec_live_xxxxxxxx" \
https://api.intelligence.devsecure.io/api/v1/rps/CVE-2021-39144Replace the placeholder with your key. Get a free API key or rank your own CVEs.
Data as of 7 Oct 2026, 05:16 UK time