XStream is a Java class library for serializing or deserializing objects into XML (JSON). Previous versions of XStream 1.4.20 had a security vulnerability. An attacker can manipulate the processed input stream and replace or inject objects, that result in a stack overflow calculating a recursive hash set causing a denial of service. This rule supports to defend the A6: Vulnerable and Outdated Components of OWASP Top 10 - 2021. Other reference:None