CVE-2021-29505 is an unsafe deserialization vulnerability in XStream versions earlier than 1.4.17. An attacker able to manipulate an input stream processed by XStream may cause deserialization of attacker-controlled content and execute commands on the host, subject to having sufficient rights. Deployments that configured XStream's security framework to allow only the minimally required types are not affected.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a proof-of-concept exploit for CVE-2021-29505, targeting the XStream Java library (version 1.4.15). The main code is in 'src/main/java/Main.java', which constructs a malicious XML payload designed to exploit insecure deserialization in XStream. The payload leverages a complex object graph involving Java classes such as javax.naming.ldap.Rdn_-RdnEntry and references to a local RMI registry at 127.0.0.1:1099. When the payload is deserialized by XStream without proper security restrictions, it can trigger dangerous behaviors, potentially leading to remote code execution. The repository includes standard Java/Maven project files and configuration, with the exploit logic self-contained in the Main.java file. No external network endpoints are hardcoded beyond the local RMI reference, and the exploit demonstrates the vulnerability rather than providing a weaponized or automated attack.
This repository contains a proof-of-concept exploit for a Java deserialization vulnerability in the XStream library, leveraging the CommonsCollections6 gadget chain. The main file, 'exp.java', constructs a malicious XML payload designed to trigger a deserialization chain when processed by a vulnerable XStream instance. The payload references an RMI server at 127.0.0.1:1099, which is typically set up using ysoserial to deliver the actual exploit chain. The README provides instructions for setting up the environment and using ysoserial to start the malicious RMI server. The exploit demonstrates how an attacker can achieve remote code execution by exploiting insecure deserialization in XStream. The repository structure is simple, consisting of a single Java exploit file and a README with usage instructions.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
XStream remote command-execution vulnerability through manipulation of processed input streams.
An XStream remote command-execution vulnerability caused by manipulation of the processed input stream.
XStream remote command-execution vulnerability through a manipulated processed input stream.
XStream remote command execution vulnerability through manipulation of the processed input stream.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.