Denial of service in XStream
High severity
GitHub Reviewed
Published
Jun 30, 2020
to the GitHub Advisory Database
•
Updated May 23, 2025
Description
Published by the National Vulnerability Database
Apr 29, 2017
Reviewed
Jun 30, 2020
Published to the GitHub Advisory Database
Jun 30, 2020
Last updated
May 23, 2025
XStream through 1.4.9, when a certain denyTypes workaround is not used, mishandles attempts to create an instance of the primitive type 'void' during unmarshalling, leading to a remote application crash, as demonstrated by an xstream.fromXML("") call.
References