External risk intelligence

XStream Remote Code Execution Vulnerability.

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2021-21346

XStream is a widely used Java serialization library embedded within numerous enterprise applications, including web servers, API gateways, and management consoles. Because it processes external input streams, vulnerabilities in its deserialization logic are frequently reachable via public-facing web or API endpoints in many standard application deployments.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A vulnerability in the XStream Java library could allow remote attackers to execute arbitrary code. This issue arises from how XStream handles input streams, and it affects users who rely on the library's default security settings rather than a specific whitelist of allowed types.

  • A library flaw could allow remote code execution.
  • Impacts systems processing untrusted input streams.
  • Confirm relevance and scope to manage risk.

Attack Path

How an attacker could exploit the issue

An attacker can exploit this vulnerability by sending a specially crafted input stream to an application that uses XStream for XML processing. This input stream manipulates XStream's deserialization process, allowing the attacker to execute arbitrary code on the remote host. This can occur without any user interaction and requires no special privileges, provided the application does not properly secure XStream's configuration.

  • No authentication or user interaction needed.
  • Triggered by processing malicious input stream.
  • Allows remote code execution.

Live Threat

Current exploitation, exposure, and threat context

When XStream's security framework is not configured with a restrictive whitelist, a remote attacker could exploit this vulnerability by manipulating processed input streams. This could allow for the loading and execution of arbitrary code from a remote host.

  • System data and application integrity at risk.
  • Exploitation via manipulated input streams.
  • Remote code execution possible.

Operational Fix

Recommended remediation, mitigation, and detection steps

Teams responsible for Java applications, libraries, and their dependencies should address this critical vulnerability. The first practical step is to identify all instances of XStream within your environment, determine which are exposed to external input, and then prioritize remediation based on business criticality and exploitability.

  • Identify application owners and libraries.
  • Verify XStream usage and exposure.
  • Plan coordinated remediation efforts.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is XStream and why is it used?

XStream is a Java library designed to convert objects to XML format and back again, a process known as serialization and deserialization. It is frequently embedded within enterprise applications, such as application servers and API gateways, to facilitate the storage or transmission of complex data structures.

What is the nature of CVE-2021-21346?

This vulnerability is classified under CWE-502, Deserialization of Untrusted Data, and CWE-434. It occurs when the library processes maliciously crafted XML input. If the security framework is not properly configured, this flaw allows the library to be manipulated into loading and executing unauthorized code from a remote host.

How can this vulnerability be triggered?

An attacker triggers this by submitting a specially crafted XML input stream to an application using a vulnerable XStream version. This action bypasses default security configurations to execute arbitrary code. The scope of impact is limited to those relying on default blacklist settings rather than a strict whitelist of minimal required types.

Why is this specific vulnerability a concern?

According to the Halo Surface Signal, this vulnerability is classified as likely because XStream is widely embedded in enterprise environments. Because it processes external input streams, these flaws are often reachable via public-facing web or API endpoints in standard deployments, posing a significant risk to application integrity.

How should teams respond to this flaw?

Teams should first update XStream to version 1.4.16 or higher. Beyond patching, they must identify all instances of the library within their environment and implement a robust security framework by establishing a strict whitelist of allowed types, moving away from reliance on default blacklist configurations.

References