Vulnerability record · CVE-2019-10173 · published 23 July 2019
CVE-2019-10173: XStream deserialization regression allows remote command execution
Xstream · Xstream
XStream 1.4.10 before 1.4.11 reintroduced a deserialization flaw that had been fixed earlier (a regression of CVE-2013-7285). When the security framework is not initialized, unmarshalling XML or other supported formats such as JSON can let a remote attacker execute arbitrary shell commands. The flaw is critical because it is network-reachable, needs no authentication or user interaction, and affects multiple Oracle products that embed XStream.
Description
It was found that xstream API version 1.4.10 before 1.4.11 introduced a regression for a previous deserialization flaw. If the security framework has not been initialized, it may allow a remote attacker to run arbitrary shell commands when unmarshalling XML or any supported format. e.g. JSON. (regression of CVE-2013-7285)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8 with network reachability, no authentication or interaction, and very high EPSS make this a top remediation priority despite no KEV listing.
What it is
XStream 1.4.10 before 1.4.11 reintroduced a deserialization flaw that had been fixed earlier (a regression of CVE-2013-7285). When the security framework is not initialized, unmarshalling XML or other supported formats such as JSON can let a remote attacker execute arbitrary shell commands. The flaw is critical because it is network-reachable, needs no authentication or user interaction, and affects multiple Oracle products that embed XStream.
Impact
An unauthenticated remote attacker can run arbitrary shell commands on the target host, leading to full compromise of confidentiality, integrity and availability. In practice this means code execution under the privileges of the application server.
Attack surface
Reached over the network by sending crafted XML or JSON to an endpoint that unmarshals data with XStream. No authentication or user interaction is required per the CVSS vector (AV:N/AC:L/PR:N/UI:N), and exploitation only works if the XStream security framework has not been initialized.
Exploitation
CVE-2019-10173 is not listed in CISA KEV and has no documented ransomware use, but EPSS is very high (0.95036, 99.858th percentile), indicating a strong likelihood of exploitation activity. References are release notes, Red Hat errata and Oracle patch advisories, with no public exploit tag in the record.
What to do
- Upgrade XStream to 1.4.11 or later, which fixes the regression.
- Apply the vendor patches referenced in the Red Hat errata and Oracle CPU advisories for affected products.
- Initialize the XStream security framework with an explicit allowlist of permitted types before unmarshalling any data.
- Avoid unmarshalling untrusted XML or JSON with XStream where possible; if required, restrict input sources and validate content.
- Inventory applications and libraries for XStream 1.4.10 and confirm no embedded copies remain unpatched.
Detection
- Search application and dependency inventories for XStream versions 1.4.10 and earlier.
- Monitor for unexpected child processes spawned by Java application servers, especially shell commands.
- Inspect logs for XStream unmarshalling errors or unusual class names in XML/JSON payloads.
- Alert on network requests to endpoints that accept XML or JSON and are handled by XStream-based code.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
10 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2019-10173 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2019-10173), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.