CVE-2021-39144 is an unsafe deserialization vulnerability in the XStream Java XML serialization library. XStream can deserialize attacker-controlled XML into unsafe sun.tracing classes when its type-security configuration relies on an insufficient blacklist or otherwise permits the relevant types. Crafted object graphs can invoke Java gadget behavior during deserialization and cause host command execution. XStream 1.4.18 changed the default security posture to stop relying on a general-purpose blacklist.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
This repository contains a single Metasploit module targeting CVE-2021-39144, a critical unauthenticated remote code execution vulnerability in VMware NSX Manager (NSX-V) and VMware Cloud Foundation 3.x. The exploit leverages an insecure XML deserialization endpoint exposed by the XStream library, allowing attackers to execute arbitrary commands as root without authentication. The module supports both in-memory command execution (e.g., reverse bash shell) and a Linux dropper (e.g., meterpreter reverse TCP), making it highly weaponized and flexible. The main attack vector is network-based, exploiting the HTTPS API endpoint '/api/2.0/services/usermgmt/password/<random>' with a crafted XML payload. The module also includes a check routine to verify if the target is a VMware NSX Manager by inspecting the '/login.jsp' page. The code is written in Ruby and is structured as a standard Metasploit exploit module, making it easy to use within the Metasploit framework. The exploit is operational and provides full root access on vulnerable appliances.
This repository demonstrates proof-of-concept exploits for multiple vulnerabilities in XStream <= 1.4.17 (CVE-2021-39141, CVE-2021-39144, CVE-2021-39150, CVE-2021-39152). The structure includes a Maven project with Java source files and a malicious XML payload. The main files are: - HttpStarter.java: Implements an HTTP server on port 8080 with a /test endpoint that accepts POST requests containing XML data. The XML is deserialized using XStream without security restrictions, making it vulnerable to RCE and SSRF attacks. - XstreamDemo.java: Demonstrates local deserialization of a malicious XML file (test.xml) using XStream, which can trigger the exploit. - test.xml: Contains a serialized Java object payload designed to exploit the deserialization vulnerability. The README provides context, affected CVEs, and usage instructions. The exploit allows attackers to send crafted XML payloads to the vulnerable endpoint, resulting in remote code execution or SSRF, depending on the payload. The repository is a functional POC for XStream deserialization vulnerabilities, suitable for both local and remote testing.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
11 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Vulnerability referenced by HPE as affecting HPE Telco Universal SLA Management <=4.6; specific technical details not provided in the bulletin excerpt.
An XStream arbitrary-code-execution vulnerability through unsafe deserialization of sun.tracing classes.
XStream arbitrary code execution through unsafe deserialization of sun.tracing classes.
XStream arbitrary code execution vulnerability via unsafe deserialization of sun.tracing classes.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.