CVE-2024-47072
published 2024-11-08CVE-2024-47072: XStream is a simple library to serialize objects to XML and back again. This vulnerability may allow a remote attacker to terminate the application with a…
PriorityP344high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
2.02%
78.8th percentile
XStream is a simple library to serialize objects to XML and back again. This vulnerability may allow a remote attacker to terminate the application with a stack overflow error resulting in a denial of service only by manipulating the processed input stream when XStream is configured to use the BinaryStreamDriver. XStream 1.4.21 has been patched to detect the manipulation in the binary input stream causing the the stack overflow and raises an InputManipulationException instead. Users are advised to upgrade. Users unable to upgrade may catch the StackOverflowError in the client code calling XStream if XStream is configured to use the BinaryStreamDriver.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | libxstream-java | < libxstream-java 1.4.20-1+deb12u1 (bookworm) | libxstream-java 1.4.20-1+deb12u1 (bookworm) |
| x-stream | xstream | < 1.4.21 | 1.4.21 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
ghsa7.5HIGH
osv7.5HIGH
vendor_debian7.5HIGH
vendor_oracle7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
CVE-2024-47072: XStream is a simple library to serialize objects to XML and back again
osv·2024-11-08·CVSS 7.5
CVE-2024-47072 [HIGH] CVE-2024-47072: XStream is a simple library to serialize objects to XML and back again
XStream is a simple library to serialize objects to XML and back again. This vulnerability may allow a remote attacker to terminate the application with a stack overflow error resulting in a denial of service only by manipulating the processed input stream when XStream is configured to use the BinaryStreamDriver. XStream 1.4.21 has been patched to detect the manipulation in the binary input stream causing the the stack overflow and raises an InputManipulationException instead. Users are advised to upgrade. Users unable to upgrade may catch the StackOverflowError in the client code calling XStream if XStream is configured to use the BinaryStreamDriver.
GHSA
XStream is vulnerable to a Denial of Service attack due to stack overflow from a manipulated binary input stream
ghsa·2024-11-07·CVSS 7.5
CVE-2024-47072 [HIGH] CWE-121 XStream is vulnerable to a Denial of Service attack due to stack overflow from a manipulated binary input stream
XStream is vulnerable to a Denial of Service attack due to stack overflow from a manipulated binary input stream
### Impact
The vulnerability may allow a remote attacker to terminate the application with a stack overflow error resulting in a denial of service only by manipulating the processed input stream when XStream is configured to use the BinaryStreamDriver.
### Patches
XStream 1.4.21 detects the manipulation in the binary input stream causing the the stack overflow and raises an InputManipulationException instead.
### Workarounds
The only solution is to catch the StackOverflowError in the client code calling XStream if XStream is configured to use the BinaryStreamDriver.
### References
See full information about the nature of the vulnerability and the steps to reproduce it in XSt
OSV
XStream is vulnerable to a Denial of Service attack due to stack overflow from a manipulated binary input stream
osv·2024-11-07·CVSS 7.5
CVE-2024-47072 [HIGH] XStream is vulnerable to a Denial of Service attack due to stack overflow from a manipulated binary input stream
XStream is vulnerable to a Denial of Service attack due to stack overflow from a manipulated binary input stream
### Impact
The vulnerability may allow a remote attacker to terminate the application with a stack overflow error resulting in a denial of service only by manipulating the processed input stream when XStream is configured to use the BinaryStreamDriver.
### Patches
XStream 1.4.21 detects the manipulation in the binary input stream causing the the stack overflow and raises an InputManipulationException instead.
### Workarounds
The only solution is to catch the StackOverflowError in the client code calling XStream if XStream is configured to use the BinaryStreamDriver.
### References
See full information about the nature of the vulnerability and the steps to reproduce it in XSt
Oracle
Oracle Oracle Communications Risk Matrix: Platform (XStream) — CVE-2024-47072
vendor_oracle·2025-07-15·CVSS 7.5
CVE-2024-47072 [HIGH] Oracle Oracle Communications Risk Matrix: Platform (XStream) — CVE-2024-47072
Oracle Oracle Communications Risk Matrix: Platform (XStream) vulnerability
CVE: CVE-2024-47072
CVSS: 7.5
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujul2025 (JUL 2025)
Oracle
Oracle Oracle Communications Applications Risk Matrix: Security (XStream) — CVE-2024-47072
vendor_oracle·2025-04-15·CVSS 7.5
CVE-2024-47072 [HIGH] Oracle Oracle Communications Applications Risk Matrix: Security (XStream) — CVE-2024-47072
Oracle Oracle Communications Applications Risk Matrix: Security (XStream) vulnerability
CVE: CVE-2024-47072
CVSS: 7.5
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuapr2025 (APR 2025)
Oracle
Oracle Oracle Fusion Middleware Risk Matrix: BAM (XStream) — CVE-2024-47072
vendor_oracle·2025-01-15·CVSS 7.5
CVE-2024-47072 [HIGH] Oracle Oracle Fusion Middleware Risk Matrix: BAM (XStream) — CVE-2024-47072
Oracle Oracle Fusion Middleware Risk Matrix: BAM (XStream) vulnerability
CVE: CVE-2024-47072
CVSS: 7.5
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujan2025 (JAN 2025)
Red Hat
com.thoughtworks.xstream: XStream is vulnerable to a Denial of Service attack due to stack overflow from a manipulated binary input stream
vendor_redhat·2024-11-07·CVSS 7.5
CVE-2024-47072 [HIGH] CWE-121 com.thoughtworks.xstream: XStream is vulnerable to a Denial of Service attack due to stack overflow from a manipulated binary input stream
com.thoughtworks.xstream: XStream is vulnerable to a Denial of Service attack due to stack overflow from a manipulated binary input stream
XStream is a simple library to serialize objects to XML and back again. This vulnerability may allow a remote attacker to terminate the application with a stack overflow error resulting in a denial of service only by manipulating the processed input stream when XStream is configured to use the BinaryStreamDriver. XStream 1.4.21 has been patched to detect the manipulation in the binary input stream causing the the stack overflow and raises an InputManipulationException instead. Users are advised to upgrade. Users unable to upgrade may catch the StackOverflowError in the client code calling XStream if XStream is configured to use the BinaryStreamDriver.
Debian
CVE-2024-47072: libxstream-java - XStream is a simple library to serialize objects to XML and back again. This vul...
vendor_debian·2024·CVSS 7.5
CVE-2024-47072 [HIGH] CVE-2024-47072: libxstream-java - XStream is a simple library to serialize objects to XML and back again. This vul...
XStream is a simple library to serialize objects to XML and back again. This vulnerability may allow a remote attacker to terminate the application with a stack overflow error resulting in a denial of service only by manipulating the processed input stream when XStream is configured to use the BinaryStreamDriver. XStream 1.4.21 has been patched to detect the manipulation in the binary input stream causing the the stack overflow and raises an InputManipulationException instead. Users are advised to upgrade. Users unable to upgrade may catch the StackOverflowError in the client code calling XStream if XStream is configured to use the BinaryStreamDriver.
Scope: local
bookworm: resolved (fixed in 1.4.20-1+deb12u1)
bullseye: resolved (fixed in 1.4.15-3+deb11u3)
forky: resolved (fixed in 1.4.21-
No detection rules found.
No public exploits indexed.
Trailofbits
Don’t recurse on untrusted input
blogs_trailofbits·2025-02-21·CVSS 7.5
[HIGH] Don’t recurse on untrusted input
A single malicious request can take down web applications that use recursive functions to process untrusted user input. We developed a simple CodeQL query to assist in finding stack overflows and used it to find denial-of-service (DoS) vulnerabilities in several high-profile Java projects. All of these projects are maintained by security-conscious organizations with robust development practices:
- ElasticSearch (in PatternBank, parseGeometryCollection)
- OpenSearch (in FilterPath, parseGeometryCollection, and validatePatternBank)
- Protocol Buffers CVE-2024-7254
- Guava Function rewrite
- XStream CVE-2024-47072
Our findings indicate that recursion, while a powerful programming tool, becomes a severe liability when used to process untrusted data in applications with availability requireme
Trailofbits
Don’t recurse on untrusted input
blogs_trailofbits·2025-02-21·CVSS 7.5
[HIGH] Don’t recurse on untrusted input
A single malicious request can take down web applications that use recursive functions to process untrusted user input. We developed a simple CodeQL query to assist in finding stack overflows and used it to find denial-of-service (DoS) vulnerabilities in several high-profile Java projects. All of these projects are maintained by security-conscious organizations with robust development practices:
ElasticSearch (in PatternBank , parseGeometryCollection )
OpenSearch (in FilterPath , parseGeometryCollection , and validatePatternBank )
Protocol Buffers CVE-2024-7254
Guava Function rewrite
XStream CVE-2024-47072
Our findings indicate that recursion, while a powerful programming tool, becomes a severe liability when used to process untrusted data in applications with availability requiremen
Bugzilla
CVE-2024-47072 com.thoughtworks.xstream: XStream is vulnerable to a Denial of Service attack due to stack overflow from a manipulated binary input stream
bugzilla·2024-11-08·CVSS 7.5
CVE-2024-47072 [HIGH] CVE-2024-47072 com.thoughtworks.xstream: XStream is vulnerable to a Denial of Service attack due to stack overflow from a manipulated binary input stream
CVE-2024-47072 com.thoughtworks.xstream: XStream is vulnerable to a Denial of Service attack due to stack overflow from a manipulated binary input stream
XStream is a simple library to serialize objects to XML and back again. This vulnerability may allow a remote attacker to terminate the application with a stack overflow error resulting in a denial of service only by manipulating the processed input stream when XStream is configured to use the BinaryStreamDriver. XStream 1.4.21 has been patched to detect the manipulation in the binary input stream causing the the stack overflow and raises an InputManipulationException instead. Users are advised to upgrade. Users unable to upgrade may catch the StackOverflowError in the client code calling XStream if XStream is configured to use the Binar
2024-11-08
Published