XStream: DoS when unmarshalling void type
Published Apr 29, 2017
7.5
HIGHCVSS 3.1
EPSS 4.93%
Description
XStream through 1.4.9, when a certain denyTypes workaround is not used, mishandles attempts to create an instance of the primitive type 'void' during unmarshalling, leading to a remote application crash, as demonstrated by an xstream.fromXML("<void/>") call.
Affected products
No data.
Configuration 1
- 1.0
- 1
Configuration 3
- 8.0
- 9.0
No data.
Red Hat JBoss A-MQ 6.3
camel
Fixed · RHSA-2017:1832
Red Hat JBoss BPMS 6.4
n/a
Fixed · RHSA-2017:2889
Red Hat JBoss BRMS 6.4
xstream
Fixed · RHSA-2017:2888
Red Hat JBoss Fuse 6.3
camel
Fixed · RHSA-2017:1832
Red Hat BPM Suite 6
xstream
Affected
Red Hat Enterprise Linux 7
xstream
Affected
Red Hat Enterprise Virtualization 3
jasperreports-server-pro
Under investigation
Red Hat JBoss A-MQ 6
camel
Affected
Red Hat JBoss Data Grid 6
xstream
Will not fix
Red Hat JBoss Data Grid 7
xstream
Affected
Red Hat JBoss Fuse Service Works 6
xstream
Will not fix
Red Hat JBoss Portal 6
xstream
Will not fix
Red Hat JBoss SOA Platform 5
xstream
Will not fix
Red Hat OpenShift Enterprise 2
xstream
Not affected
Red Hat Satellite 6
xstream
Not affected
Red Hat Single Sign-On 7
rh-sso7-keycloak
Affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat JBoss A-MQ 6.3 | camel | Fixed | RHSA-2017:1832 |
| Red Hat JBoss BPMS 6.4 | n/a | Fixed | RHSA-2017:2889 |
| Red Hat JBoss BRMS 6.4 | xstream | Fixed | RHSA-2017:2888 |
| Red Hat JBoss Fuse 6.3 | camel | Fixed | RHSA-2017:1832 |
| Red Hat BPM Suite 6 | xstream | Affected | n/a |
| Red Hat Enterprise Linux 7 | xstream | Affected | n/a |
| Red Hat Enterprise Virtualization 3 | jasperreports-server-pro | Under investigation | n/a |
| Red Hat JBoss A-MQ 6 | camel | Affected | n/a |
| Red Hat JBoss Data Grid 6 | xstream | Will not fix | n/a |
| Red Hat JBoss Data Grid 7 | xstream | Affected | n/a |
| Red Hat JBoss Fuse Service Works 6 | xstream | Will not fix | n/a |
| Red Hat JBoss Portal 6 | xstream | Will not fix | n/a |
| Red Hat JBoss SOA Platform 5 | xstream | Will not fix | n/a |
| Red Hat OpenShift Enterprise 2 | xstream | Not affected | n/a |
| Red Hat Satellite 6 | xstream | Not affected | n/a |
| Red Hat Single Sign-On 7 | rh-sso7-keycloak | Affected | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
1 other source (Red Hat) ▾
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
AV:N/AC:L/Au:N/C:N/I:N/A:P
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2021–2026- EPSS v1
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v1
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (23 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 4.93% (0.04928) | 91.86th | v5 (v2026.06.15) |
| Jun 15, 2026 | 5.06% (0.05064) | 91.19th | v5 (v2026.06.15) |
| Nov 21, 2025 | 2.95% (0.02946) | 85.95th | v4 (v2025.03.14) |
| Nov 18, 2025 | 9.23% (0.09234) | 91.87th | v4 (v2025.03.14) |
| Oct 6, 2025 | 2.95% (0.02946) | 85.93th | v4 (v2025.03.14) |
| Apr 30, 2025 | 4.20% (0.04201) | 88.06th | v4 (v2025.03.14) |
| Mar 30, 2025 | 5.40% (0.05401) | 89.16th | v4 (v2025.03.14) |
| Mar 29, 2025 | 11.09% (0.11095) | 89.07th | v4 (v2025.03.14) |
| Mar 17, 2025 | 4.90% (0.04899) | 88.86th | v4 (v2025.03.14) |
| Dec 17, 2024 | 86.28% (0.86279) | 98.82th | v3 (v2023.03.01) |
| Oct 9, 2024 | 74.59% (0.74585) | 98.20th | v3 (v2023.03.01) |
| Aug 3, 2023 | 79.30% (0.79296) | 97.83th | v3 (v2023.03.01) |
| Jun 25, 2023 | 83.00% (0.83001) | 97.93th | v3 (v2023.03.01) |
| May 8, 2023 | 85.07% (0.85073) | 97.98th | v3 (v2023.03.01) |
| Mar 7, 2023 | 87.04% (0.87038) | 97.98th | v3 (v2023.03.01) |
| Mar 6, 2023 | 1.54% (0.01537) | 74.52th | v2 (v2022.01.01) |
| Feb 23, 2023 | 1.54% (0.01537) | 74.48th | v2 (v2022.01.01) |
| Apr 1, 2022 | 1.54% (0.01537) | 72.41th | v2 (v2022.01.01) |
| Feb 4, 2022 | 1.54% (0.01537) | 51.33th | v2 (v2022.01.01) |
| Feb 3, 2022 | 2.07% (0.02069) | 50.36th | v1 |
| Jan 6, 2022 | 2.07% (0.02069) | 49.86th | v1 |
| Sep 1, 2021 | 2.07% (0.02069) | 77.27th | v1 |
| Apr 14, 2021 | 2.07% (0.02069) | 0.00th | v1 |
References (17)
- http://www.debian.org/security/2017/dsa-3841 vendor-advisoryx_refsource_DEBIANMailing ListThird Party Advisory
- http://www.securityfocus.com/bid/100687 vdb-entryx_refsource_BIDBroken LinkThird Party AdvisoryVDB Entry
- http://www.securitytracker.com/id/1039499 vdb-entryx_refsource_SECTRACKBroken LinkThird Party AdvisoryVDB Entry
- http://x-stream.github.io/CVE-2017-7957.html x_refsource_CONFIRMVendor Advisory
- https://access.redhat.com/errata/RHSA-2017:1832 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2017:2888 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2017:2889 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/security/cve/CVE-2017-7957 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1441538 Issue Tracking
- https://exchange.xforce.ibmcloud.com/vulnerabilities/125800 vdb-entryx_refsource_XFThird Party AdvisoryVDB Entry
- https://github.com/advisories/GHSA-7hwc-46rm-65jh Advisory
- https://github.com/x-stream/xstream/commit/6e546ec366419158b1e393211be6d78ab9604ab
- https://github.com/x-stream/xstream/commit/8542d02d9ac5d384c85f4b33d6c1888c53bd55d
- https://github.com/x-stream/xstream/commit/b3570be2f39234e61f99f9a20640756ea71b1b4
- https://nvd.nist.gov/vuln/detail/CVE-2017-7957
- https://www-prd-trops.events.ibm.com/node/715749 x_refsource_CONFIRMBroken LinkPermissions Required
- https://www.cve.org/CVERecord?id=CVE-2017-7957
Change history (0)
No recorded changes yet.