References https://cn-sec.com/archives/tag/xstream https://www.secrss.com/articles/50473 https://it.ruc.edu.cn/wlaq/c597ca0992b4440ba43000ed10421475.htm https://download.sangfor.com.cn/bc452bec412b4fe2bdbbc673bb5ae00f.pdf https://blog.nsfocus.net/xstream-se/ https://www.iovz.com/announce-details.html?id=10 https://www.anquanke.com/post/id/301739 https://www.oscs1024.com/blog/2023/01/01/%E5%AE%89%E5%85%A8%E5%91%A8%E6%8A%A5%E7%AC%AC24%E6%9C%9F/ https://github.com/x-stream/xstream/security/advisories/GHSA-hfq9-hggm-c56q https://x-stream.github.io/security.html https://security.snyk.io/package/maven/com.thoughtworks.xstream%3Axstream/1.4.10 https://www.hillstonenet.com/blog/breaking-the-mold-halting-a-hackers-code-ep-9-xstream-stack-overflow-denial-of-service-vulnerability/
Related VulnerabilitiesPoCclaude-settings-exposure: Claude Code Project Settings Exposure关于用友GRP-U8Cloud产品getBudgetReleaseProjectList及U8AppProxy及fbpm-modeler存在命令执行漏洞的安全通告FOGProject /fog/management/export.php 信息泄露漏洞(CVE-2025-58443)PoCCVE-2026-47717: FUXA 1.3.0 - Unauthenticated ICS/SCADA Project Data DisclosureTRUfusion Enterprise /trufusionPortal/getProjectList 权限绕过漏洞(CVE-2025-27223)FUXA /api/project 信息泄露漏洞(CVE-2026-47717)孚盟云 CRM /PageStructure/Normal/TfrmProject.aspx 文件读取漏洞PoCopenproject-default-login: OpenProject - Default Admin CredentialsFUXA /api/project 权限绕过漏洞(CVE-2025-69971)OpenProject存在默认口令PoCCVE-2024-13114: WP Projects Portfolio <= 3.0 - Cross-Site ScriptingPoCFOG Project /fog/service/getversion.php 文件读取漏洞(CVE-2026-24138)