← Vulnerability feed

Vulnerability record · CVE-2019-10173 · published 23 July 2019

CVE-2019-10173: XStream deserialization regression allows remote command execution

Xstream · Xstream

XStream 1.4.10 before 1.4.11 reintroduced a deserialization flaw that had been fixed earlier (a regression of CVE-2013-7285). When the security framework is not initialized, unmarshalling XML or other supported formats such as JSON can let a remote attacker execute arbitrary shell commands. The flaw is critical because it is network-reachable, needs no authentication or user interaction, and affects multiple Oracle products that embed XStream.

9.8 CVSS 3.1 Critical EPSS 95% · top 0.1% CWE-94 · Code injectionCWE-502 · Deserialization of untrusted data
9.8CVSS 3.1 base score, v2 7.5
95%EPSS exploitation probability, 30 days
NoNot in CISA KEV
10Affected product versions listed by NVD
22References
17 Jun 2026Last modified by NVD

Description

It was found that xstream API version 1.4.10 before 1.4.11 introduced a regression for a previous deserialization flaw. If the security framework has not been initialized, it may allow a remote attacker to run arbitrary shell commands when unmarshalling XML or any supported format. e.g. JSON. (regression of CVE-2013-7285)

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: high.

critical priorityCVSS 9.8 with network reachability, no authentication or interaction, and very high EPSS make this a top remediation priority despite no KEV listing.

What it is

XStream 1.4.10 before 1.4.11 reintroduced a deserialization flaw that had been fixed earlier (a regression of CVE-2013-7285). When the security framework is not initialized, unmarshalling XML or other supported formats such as JSON can let a remote attacker execute arbitrary shell commands. The flaw is critical because it is network-reachable, needs no authentication or user interaction, and affects multiple Oracle products that embed XStream.

Impact

An unauthenticated remote attacker can run arbitrary shell commands on the target host, leading to full compromise of confidentiality, integrity and availability. In practice this means code execution under the privileges of the application server.

Attack surface

Reached over the network by sending crafted XML or JSON to an endpoint that unmarshals data with XStream. No authentication or user interaction is required per the CVSS vector (AV:N/AC:L/PR:N/UI:N), and exploitation only works if the XStream security framework has not been initialized.

Exploitation

CVE-2019-10173 is not listed in CISA KEV and has no documented ransomware use, but EPSS is very high (0.95036, 99.858th percentile), indicating a strong likelihood of exploitation activity. References are release notes, Red Hat errata and Oracle patch advisories, with no public exploit tag in the record.

What to do

  • Upgrade XStream to 1.4.11 or later, which fixes the regression.
  • Apply the vendor patches referenced in the Red Hat errata and Oracle CPU advisories for affected products.
  • Initialize the XStream security framework with an explicit allowlist of permitted types before unmarshalling any data.
  • Avoid unmarshalling untrusted XML or JSON with XStream where possible; if required, restrict input sources and validate content.
  • Inventory applications and libraries for XStream 1.4.10 and confirm no embedded copies remain unpatched.

Detection

  • Search application and dependency inventories for XStream versions 1.4.10 and earlier.
  • Monitor for unexpected child processes spawned by Java application servers, especially shell commands.
  • Inspect logs for XStream unmarshalling errors or unusual class names in XML/JSON payloads.
  • Alert on network requests to endpoints that accept XML or JSON and are handled by XStream-based code.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

10 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://x-stream.github.io/changes.html#1.4.11 Release NotesThird Party Advisory
https://access.redhat.com/errata/RHSA-2019:3892 Third Party Advisory
https://access.redhat.com/errata/RHSA-2019:4352 Third Party Advisory
https://access.redhat.com/errata/RHSA-2020:0445 Third Party Advisory
https://access.redhat.com/errata/RHSA-2020:0727 Third Party Advisory
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-10173 Issue TrackingThird Party Advisory
https://www.oracle.com//security-alerts/cpujul2021.html PatchThird Party Advisory
https://www.oracle.com/security-alerts/cpuApr2021.html PatchThird Party Advisory
https://www.oracle.com/security-alerts/cpuapr2020.html Third Party Advisory
https://www.oracle.com/security-alerts/cpujan2021.html Third Party Advisory
https://www.oracle.com/security-alerts/cpuoct2020.html Third Party Advisory
http://x-stream.github.io/changes.html#1.4.11 Release NotesThird Party Advisory
https://access.redhat.com/errata/RHSA-2019:3892 Third Party Advisory
https://access.redhat.com/errata/RHSA-2019:4352 Third Party Advisory
https://access.redhat.com/errata/RHSA-2020:0445 Third Party Advisory
https://access.redhat.com/errata/RHSA-2020:0727 Third Party Advisory
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-10173 Issue TrackingThird Party Advisory
https://www.oracle.com//security-alerts/cpujul2021.html PatchThird Party Advisory
https://www.oracle.com/security-alerts/cpuApr2021.html PatchThird Party Advisory
https://www.oracle.com/security-alerts/cpuapr2020.html Third Party Advisory
https://www.oracle.com/security-alerts/cpujan2021.html Third Party Advisory
https://www.oracle.com/security-alerts/cpuoct2020.html Third Party Advisory

Track CVE-2019-10173 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2022-22965Spring Framework data binding remote code execution (Spring4Shell)Spring MVC and Spring WebFlux applications on JDK 9+ can be exploited through data binding to achieve remote code execution. The known exploit path r…KEVEPSS 100%analysed9.8CVE-2020-2555Oracle Coherence T3 deserialization allows unauthenticated remote code executionOracle Coherence (Fusion Middleware) deserializes untrusted data reachable over the T3 protocol, allowing an unauthenticated network attacker to exec…KEVEPSS 97%analysed9.8CVE-2017-9841PHPUnit eval-stdin.php remote PHP code executionPHPUnit before 4.8.28 and 5.x before 5.6.3 ships Util/PHP/eval-stdin.php, which evaluates HTTP POST body content as PHP when it begins with a "<?php …KEVEPSS 100%analysed8.5CVE-2021-39144XStream deserialization allows remote command executionXStream, a Java library that serializes objects to and from XML, can execute host commands when a remote attacker with sufficient rights manipulates …KEVEPSS 98%analysed6.1CVE-2020-11023jQuery DOM manipulation methods XSS via untrusted HTML option elementsjQuery versions 1.0.3 through before 3.5.0 execute untrusted code when HTML containing <option> elements from untrusted sources is passed to DOM mani…KEVEPSS 85%analysed10.0CVE-2018-14721Fasterxml jackson-databind server-side request forgery (ssrf) vulnerabilityFasterXML jackson-databind 2.x before 2.9.7 might allow remote attackers to conduct server-side request forgery (SSRF) attacks by leveraging failure …EPSS 10%9.9CVE-2021-21345XStream deserialization allows remote command executionXStream before 1.4.16 deserializes untrusted XML without adequate type restrictions, allowing code injection and OS command execution. The flaw is a …EPSS 72%analysed9.8CVE-2022-23305Log4j 1.x JDBCAppender SQL injection via logged inputThe JDBCAppender in Log4j 1.2.x builds SQL statements from configuration parameters and PatternLayout converters, so logged values such as the %m mes…EPSS 67%analysed

Source: NIST National Vulnerability Database (record CVE-2019-10173), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.