AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2021-39152

HIGH · CVSS 8.5 EPSS 11.38% Public Exploit

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2021-08-23 · Last synced 2026-08-04

CyberRota Analysis

This is a high severity vulnerability with a CVSS score of 8.5. It affects Java, GitHub. Public exploit code or proof-of-concept references have been detected in its references. Its EPSS score suggests a 11.4% probability of exploitation in the next 30 days. It may be remotely exploitable.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2021-39152
Severity
HIGH
CVSS
8.5
EPSS
11.38%
Java GitHub

Original NVD Description

XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to request data from internal resources that are not publicly available only by manipulating the processed input stream with a Java runtime version 14 to 8. No user is affected, who followed the recommendation to setup XStream's security framework with a whitelist limited to the minimal required types. If you rely on XStream's default blacklist of the [Security Framework](https://x-stream.github.io/security.html#framework), you will have to use at least version 1.4.18.

Related CVEs

Other vulnerabilities affecting the same vendor(s)