[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"repo-stars":3,"vuln-CVE-2024-47072":6},{"stargazers_count":4,"fetched_at":5},7,"2026-06-05T14:55:33.319Z",{"id":7,"descriptions":8,"cisa":9,"weaknesses":10,"exploits":31,"aliases":32,"duplicate_of":9,"upstream":34,"downstream":35,"duplicates":58,"related":59,"reserved_at":9,"published_at":66,"modified_at":67,"state":68,"summary":69,"references_raw":78,"kevs":114,"epss":115,"epss_history":118,"metrics":393,"affected":406},"CVE-2024-47072","XStream is a simple library to serialize objects to XML and back again. This vulnerability may allow a remote attacker to terminate the application with a stack overflow error resulting in a denial of service only by manipulating the processed input stream when XStream is configured to use the BinaryStreamDriver. XStream 1.4.21 has been patched to detect the manipulation in the binary input stream causing the the stack overflow and raises an InputManipulationException instead. Users are advised to upgrade. Users unable to upgrade may catch the StackOverflowError in the client code calling XStream if XStream is configured to use the BinaryStreamDriver.",null,[11,20],{"_key":12,"id":12,"name":13,"description":14,"type":15,"status":16,"abstraction":17,"likelihood_of_exploit":18,"capec":19},"CWE-121","Stack-based Buffer Overflow","A stack-based buffer overflow condition is a condition where the buffer being overwritten is allocated on the stack (i.e., is a local variable or, rarely, a parameter to a function).","weakness","Draft","Variant","High",[],{"_key":21,"id":21,"name":22,"description":23,"type":15,"status":16,"abstraction":24,"likelihood_of_exploit":25,"capec":26},"CWE-502","Deserialization of Untrusted Data","The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.","Base","Medium",[27],{"id":28,"name":29,"techniques":30},"CAPEC-586","Object Injection",[],[],[33],"GHSA-hfq9-hggm-c56q",[],[36,38,40,42,44,46,48,50,52,54,56],{"_key":37},"SUSE-SU-2024:4037-1",{"_key":39},"OPENSUSE-SU-2024:14480-1",{"_key":41},"DLA-4001-1",{"_key":43},"DEBIAN-CVE-2024-47072",{"_key":45},"RHSA-2025:2218",{"_key":47},"RHSA-2025:2219",{"_key":49},"RHSA-2025:2220",{"_key":51},"RHSA-2025:2221",{"_key":53},"RHSA-2025:2222",{"_key":55},"RHSA-2025:2223",{"_key":57},"UBUNTU-CVE-2024-47072",[],[60,61,62,64],{"_key":37},{"_key":39},{"_key":63},"CGA-CC2C-9VQH-97J8",{"_key":65},"CGA-JMPQ-87GQ-8J3R","2024-11-07T23:38:52.978Z","2025-11-03T22:19:56.488Z","Deferred",{"cisa_kev":70,"cisa_ransomware":70,"cisa_vendor":9,"epss_severity":71,"epss_score":72,"severity":73,"severity_score":74,"severity_version":75,"severity_source":76,"severity_vector":77,"severity_status":68},false,"low",0.00261,"high",7.5,"v3.1","cve.org","CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",[79,87,92,96,100,105,109],{"url":80,"sources":81,"tags":84},"https://github.com/x-stream/xstream/security/advisories/GHSA-hfq9-hggm-c56q",[76,82,83],"nvd","osv_maven",[85,86],"X Refsource CONFIRM","WEB",{"url":88,"sources":89,"tags":90},"https://github.com/x-stream/xstream/commit/bb838ce2269cac47433e31c77b2b236466e9f266",[76,82,83],[91,86],"X Refsource MISC",{"url":93,"sources":94,"tags":95},"https://x-stream.github.io/CVE-2024-47072.html",[76,82,83],[91,86],{"url":97,"sources":98,"tags":99},"https://lists.debian.org/debian-lts-announce/2024/12/msg00023.html",[76,82,83],[86],{"url":101,"sources":102,"tags":103},"https://nvd.nist.gov/vuln/detail/CVE-2024-47072",[83],[104],"Advisory",{"url":106,"sources":107,"tags":108},"https://github.com/x-stream/xstream/commit/fdd9f7d3de0d7ccf2f9979bcd09fbf3e6a0c881a",[83],[86],{"url":110,"sources":111,"tags":112},"https://github.com/x-stream/xstream",[83],[113],"PACKAGE",[],{"date":116,"score":72,"percentile":117},"2026-06-04",0.49652,[119,123,126,130,133,136,139,142,145,148,151,154,157,160,163,167,170,173,176,179,182,185,188,191,194,198,201,204,207,209,212,215,218,221,224,227,230,233,236,239,242,245,248,252,256,259,262,265,268,271,274,277,280,283,286,289,291,294,297,301,304,307,310,313,316,319,322,325,328,331,334,337,339,341,344,347,350,353,357,360,363,366,369,372,375,378,381,384,386,389],{"date":120,"score":121,"percentile":122},"2025-11-04",0.00144,0.35259,{"date":124,"score":121,"percentile":125},"2025-11-05",0.35244,{"date":127,"score":128,"percentile":129},"2025-11-06",0.00176,0.39463,{"date":131,"score":128,"percentile":132},"2025-11-07",0.39488,{"date":134,"score":128,"percentile":135},"2025-11-08",0.39481,{"date":137,"score":128,"percentile":138},"2025-11-09",0.39466,{"date":140,"score":128,"percentile":141},"2025-11-10",0.39431,{"date":143,"score":128,"percentile":144},"2025-11-11",0.3945,{"date":146,"score":128,"percentile":147},"2025-11-12",0.39485,{"date":149,"score":128,"percentile":150},"2025-11-13",0.395,{"date":152,"score":128,"percentile":153},"2025-11-14",0.39501,{"date":155,"score":128,"percentile":156},"2025-11-15",0.39496,{"date":158,"score":128,"percentile":159},"2025-11-16",0.39477,{"date":161,"score":128,"percentile":162},"2025-11-17",0.39451,{"date":164,"score":165,"percentile":166},"2025-11-18",0.00733,0.70513,{"date":168,"score":165,"percentile":169},"2025-11-19",0.70521,{"date":171,"score":165,"percentile":172},"2025-11-20",0.70531,{"date":174,"score":121,"percentile":175},"2025-11-21",0.35264,{"date":177,"score":128,"percentile":178},"2025-11-22",0.39453,{"date":180,"score":128,"percentile":181},"2025-11-23",0.39425,{"date":183,"score":128,"percentile":184},"2025-11-24",0.39415,{"date":186,"score":128,"percentile":187},"2025-11-25",0.39427,{"date":189,"score":128,"percentile":190},"2025-11-26",0.3942,{"date":192,"score":128,"percentile":193},"2025-11-27",0.39429,{"date":195,"score":196,"percentile":197},"2025-11-28",0.0017,0.3859,{"date":199,"score":196,"percentile":200},"2025-11-29",0.38564,{"date":202,"score":196,"percentile":203},"2025-11-30",0.38549,{"date":205,"score":128,"percentile":206},"2025-12-01",0.39479,{"date":208,"score":128,"percentile":132},"2025-12-02",{"date":210,"score":128,"percentile":211},"2025-12-03",0.3949,{"date":213,"score":196,"percentile":214},"2025-12-04",0.38543,{"date":216,"score":196,"percentile":217},"2025-12-05",0.38576,{"date":219,"score":196,"percentile":220},"2025-12-06",0.38575,{"date":222,"score":196,"percentile":223},"2025-12-07",0.38552,{"date":225,"score":196,"percentile":226},"2025-12-08",0.38567,{"date":228,"score":196,"percentile":229},"2025-12-09",0.3861,{"date":231,"score":196,"percentile":232},"2025-12-10",0.38669,{"date":234,"score":196,"percentile":235},"2025-12-11",0.38699,{"date":237,"score":196,"percentile":238},"2025-12-12",0.38733,{"date":240,"score":196,"percentile":241},"2025-12-13",0.38709,{"date":243,"score":196,"percentile":244},"2025-12-14",0.38671,{"date":246,"score":196,"percentile":247},"2025-12-15",0.38645,{"date":249,"score":250,"percentile":251},"2025-12-16",0.00456,0.63213,{"date":253,"score":254,"percentile":255},"2025-12-17",0.00354,0.57173,{"date":257,"score":254,"percentile":258},"2025-12-18",0.5721,{"date":260,"score":254,"percentile":261},"2025-12-19",0.57217,{"date":263,"score":254,"percentile":264},"2025-12-20",0.57214,{"date":266,"score":254,"percentile":267},"2025-12-21",0.57195,{"date":269,"score":254,"percentile":270},"2025-12-22",0.57176,{"date":272,"score":254,"percentile":273},"2025-12-23",0.57183,{"date":275,"score":254,"percentile":276},"2025-12-24",0.57194,{"date":278,"score":254,"percentile":279},"2025-12-25",0.57238,{"date":281,"score":254,"percentile":282},"2025-12-26",0.57232,{"date":284,"score":254,"percentile":285},"2025-12-27",0.5729,{"date":287,"score":254,"percentile":288},"2025-12-28",0.57203,{"date":290,"score":254,"percentile":276},"2025-12-29",{"date":292,"score":254,"percentile":293},"2025-12-30",0.57193,{"date":295,"score":254,"percentile":296},"2025-12-31",0.57228,{"date":298,"score":299,"percentile":300},"2026-01-01",0.0043,0.62179,{"date":302,"score":299,"percentile":303},"2026-01-02",0.62165,{"date":305,"score":299,"percentile":306},"2026-01-03",0.62162,{"date":308,"score":254,"percentile":309},"2026-01-04",0.57201,{"date":311,"score":254,"percentile":312},"2026-01-05",0.57189,{"date":314,"score":254,"percentile":315},"2026-01-06",0.572,{"date":317,"score":254,"percentile":318},"2026-01-07",0.57225,{"date":320,"score":254,"percentile":321},"2026-01-08",0.57247,{"date":323,"score":254,"percentile":324},"2026-01-09",0.5725,{"date":326,"score":254,"percentile":327},"2026-01-10",0.57248,{"date":329,"score":254,"percentile":330},"2026-01-11",0.57231,{"date":332,"score":254,"percentile":333},"2026-01-12",0.57196,{"date":335,"score":254,"percentile":336},"2026-01-13",0.57167,{"date":338,"score":254,"percentile":258},"2026-01-14",{"date":340,"score":254,"percentile":264},"2026-01-15",{"date":342,"score":254,"percentile":343},"2026-01-16",0.57239,{"date":345,"score":254,"percentile":346},"2026-01-17",0.57229,{"date":348,"score":254,"percentile":349},"2026-01-18",0.5723,{"date":351,"score":254,"percentile":352},"2026-01-19",0.57216,{"date":354,"score":355,"percentile":356},"2026-01-20",0.00364,0.5793,{"date":358,"score":355,"percentile":359},"2026-01-21",0.57934,{"date":361,"score":355,"percentile":362},"2026-01-22",0.57933,{"date":364,"score":355,"percentile":365},"2026-01-23",0.5797,{"date":367,"score":355,"percentile":368},"2026-01-24",0.57979,{"date":370,"score":355,"percentile":371},"2026-01-25",0.57942,{"date":373,"score":355,"percentile":374},"2026-01-26",0.57925,{"date":376,"score":355,"percentile":377},"2026-01-27",0.57935,{"date":379,"score":355,"percentile":380},"2026-01-28",0.5794,{"date":382,"score":355,"percentile":383},"2026-01-29",0.57941,{"date":385,"score":355,"percentile":371},"2026-01-30",{"date":387,"score":355,"percentile":388},"2026-01-31",0.57943,{"date":390,"score":391,"percentile":392},"2026-02-01",0.00442,0.62899,[394,399,401],{"source":76,"cvss_v2_0":9,"cvss_v3_0":9,"cvss_v3_1":395,"cvss_v4_0":9},{"baseScore":74,"baseSeverity":396,"vectorString":77,"impactScore":397,"exploitabilityScore":398},"HIGH",6,10,{"source":82,"cvss_v2_0":9,"cvss_v3_0":9,"cvss_v3_1":400,"cvss_v4_0":9},{"baseScore":74,"baseSeverity":396,"vectorString":77,"impactScore":397,"exploitabilityScore":398},{"source":83,"cvss_v2_0":9,"cvss_v3_0":9,"cvss_v3_1":402,"cvss_v4_0":403},{"baseScore":74,"baseSeverity":9,"vectorString":77,"impactScore":397,"exploitabilityScore":398},{"baseScore":404,"baseSeverity":9,"vectorString":405,"impactScore":9,"exploitabilityScore":9},8.7,"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:P",[407,420],{"ecosystem":408,"name":409,"vendor":410,"product":411,"cpe_part":9,"purl_type":412,"purl_namespace":410,"purl_name":411,"source":9,"versions":413},"Maven","com.thoughtworks.xstream:xstream","com.thoughtworks.xstream","xstream","maven",[414],{"version":415,"is_range":416,"range_type":417,"version_start":9,"version_start_type":9,"version_end":418,"version_end_type":419,"fixed_in":9},"lt1_4_21",true,"ecosystem","1.4.21","excluding",{"ecosystem":9,"name":411,"vendor":421,"product":411,"cpe_part":422,"purl_type":9,"purl_namespace":9,"purl_name":9,"source":9,"versions":423},"x-stream","a",[424],{"version":425,"is_range":416,"range_type":76,"version_start":9,"version_start_type":9,"version_end":418,"version_end_type":419,"fixed_in":9},"\u003C 1.4.21"]