← back
CVE-2022-40151

Stack Buffer Overflow in xstream

CVSS 6.5 MEDIUMEPSS 1.0%CWE-121
Vexday Risk Score
13Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 6.5EPSS 1.0%KEV nãoPoC Nuclei Metasploit Patch
Lifecycle
16 Sep 2022Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
Those using Xstream to seralize XML data may be vulnerable to Denial of Service attacks (DOS). If the parser is running on user supplied input, an attacker may supply content that causes the parser to crash by stackoverflow. This effect may support a denial of service attack.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Affected products
xstream · xstream

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →