Fix XStream — CVE-2022-40151 HIGH

Fix CVE-2022-40151 (HIGH) in XStream for Java/Maven. Paste your pom.xml into PackageFix and get a patched version — no CLI, no signup. Denial of service via crafted xml with reference cycles.

⚠ Vulnerability

CVE-2022-40151 (HIGH) — denial of service via crafted XML with reference cycles in XStream below 1.4.20.

Vulnerable — pom.xml

1.4.18

Fixed — pom.xml

1.4.20
✓ Fix

Update XStream to 1.4.20 and run mvn dependency:resolve.

Paste your manifest — get back a fixed version with all CVEs patched in seconds.

Open PackageFix →

No signup · No CLI · No GitHub connection · Runs 100% in your browser

CVE Details

FieldValue
CVE IDCVE-2022-40151
SeverityHIGH
PackageXStream (Java/Maven)
Safe version1.4.20
CISA KEV
DescriptionDenial of service via crafted xml with reference cycles

Frequently Asked Questions

What is CVE-2022-40151?
CVE-2022-40151 is a HIGH severity vulnerability in XStream (Java/Maven) that allows denial of service via crafted XML with reference cycles. Update to 1.4.20 or later.
How do I fix CVE-2022-40151 in XStream?
Update XStream to version 1.4.20 in your pom.xml and run mvn dependency:resolve.
Is CVE-2022-40151 being actively exploited?
Check packagefix.dev — the CISA KEV catalog updates daily.
How do I verify the fix for CVE-2022-40151?
After updating, paste your pom.xml into PackageFix again. If CVE-2022-40151 no longer appears in the CVE table, the fix is applied.

Related Guides