Vulnerabilities > Xstream Project > Xstream > 1.4.18

DATE CVE VULNERABILITY TITLE RISK
2022-12-28 CVE-2022-41966 Uncontrolled Recursion vulnerability in Xstream Project Xstream
XStream serializes Java objects to XML and back again.
network
low complexity
xstream-project CWE-674
7.5
2022-09-16 CVE-2022-40152 Out-of-bounds Write vulnerability in multiple products
Those using Woodstox to parse XML data may be vulnerable to Denial of Service attacks (DOS) if DTD support is enabled.
network
low complexity
xstream-project fasterxml CWE-787
7.5
2022-02-01 CVE-2021-43859 Resource Exhaustion vulnerability in multiple products
XStream is an open source java library to serialize objects to XML and back again.
7.5