Vulnerability record · CVE-2021-21345 · published 23 March 2021
CVE-2021-21345: XStream deserialization allows remote command execution
NNetapp · Oncommand Insight
XStream before 1.4.16 deserializes untrusted XML without adequate type restrictions, allowing code injection and OS command execution. The flaw is a deserialization of untrusted data issue (CWE-502) that also enables code and command injection. Systems relying on XStream's default blacklist rather than a minimal whitelist are exposed.
Description
XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a remote attacker who has sufficient rights to execute commands of the host only by manipulating the processed input stream. No user is affected, who followed the recommendation to setup XStream's security framework with a whitelist limited to the minimal required types. If you rely on XStream's default blacklist of the Security Framework, you will have to use at least version 1.4.16.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.9 with network reachability, low privileges, and high EPSS indicate severe risk of remote code execution.
What it is
XStream before 1.4.16 deserializes untrusted XML without adequate type restrictions, allowing code injection and OS command execution. The flaw is a deserialization of untrusted data issue (CWE-502) that also enables code and command injection. Systems relying on XStream's default blacklist rather than a minimal whitelist are exposed.
Impact
An attacker with sufficient rights can execute arbitrary commands on the host by manipulating the processed input stream. This can lead to full compromise of the application and underlying system.
Attack surface
Reachable over the network via crafted XML input to an XStream deserialization endpoint. The CVSS vector indicates low privileges are required and no user interaction is needed.
Exploitation
Not listed in CISA KEV, but EPSS is very high (0.72324, 99.4th percentile) and a public exploit reference exists. No ransomware groups are documented as using it.
What to do
- Upgrade XStream to version 1.4.16 or later.
- Configure XStream's security framework with a whitelist limited to the minimal required types.
- Apply vendor patches for affected products (Oracle, NetApp, Debian, Fedora, Apache ActiveMQ, JMeter).
- Avoid deserializing untrusted XML input where possible.
Detection
- Monitor for XML payloads containing XStream-specific class or method references in deserialization endpoints.
- Alert on unexpected child processes spawned by Java application servers.
- Review application logs for deserialization errors or unusual class loading.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
16 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2021-21345 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2021-21345), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.