Vulnerabilities

ID
Packages
Summary
Published
arrow_upward
Attributes
CVE-2026-49832
  • github.com/dspace/dspace
DSpace: Remote Code Execution (RCE) possible in Velocity Templates used by LDN 02 Sep
  • Fix available
  • Severity - 8.0 (High)
CVE-2026-49833
  • github.com/dspace/dspace
DSpace: Path Traversal possible in LDN message generation 02 Sep
  • Fix available
  • Severity - 5.5 (Medium)
CVE-2026-49831
  • github.com/dspace/dspace
DSpace: Curation Task Reporter output path is not restricted to trusted directories (Path Traversal Vulnerability) 02 Sep
  • Fix available
  • Severity - 5.5 (Medium)
CVE-2026-49830
  • github.com/dspace/dspace
DSpace: ORE resource URI does not validate scheme for non-web resources 02 Sep
  • Fix available
  • Severity - 4.4 (Medium)
GHSA-9qm4-rh6w-pq5x
  • Maven/org.dspace:dspace-api
DSpace: Path Traversal is possible through LDN message generation 08 Jul
  • Fix available
  • Severity - 5.5 (Medium)
GHSA-c827-pw3m-67w7
  • Maven/org.dspace:dspace-api
DSpace: ORE resource URI does not validate scheme for non-web resources 08 Jul
  • Fix available
  • Severity - 4.4 (Medium)
GHSA-v66x-68f2-pxf5
  • Maven/org.dspace:dspace-api
DSpace has a possible Path Traversal Vulnerability in its Curation Task Reporter output path 08 Jul
  • Fix available
  • Severity - 5.5 (Medium)
GHSA-9x82-rm84-c6x7
  • Maven/org.dspace:dspace-api
DSpace has possible Remote Code Execution (RCE) through Velocity Templates used by LDN 08 Jul
  • Fix available
  • Severity - 8.0 (High)
GHSA-vhvx-8xgc-99wf
  • Maven/org.dspace:dspace-api
DSpace is vulnerable to Path Traversal attacks when importing packages using Simple Archive Format 15 Jul 2025
  • Fix available
  • Severity - 5.2 (Medium)
GHSA-jjwr-5cfh-7xwh
  • Maven/org.dspace:dspace-api
DSpace is vulnerable to XML External Entity injection during archive imports 15 Jul 2025
  • Fix available
  • Severity - 6.9 (Medium)
CVE-2025-53622
  • github.com/dspace/dspace
DSpace has path traversal vulnerability in Simple Archive Format (SAF) package import via contents file 15 Jul 2025
  • Fix available
  • Severity - 5.2 (Medium)
CVE-2025-53621
  • github.com/dspace/dspace
DSpace vulnerable to XML External Entity (XXE) injection in import via Simple Archive Format (SAF) or import from external sources 15 Jul 2025
  • Fix available
  • Severity - 6.9 (Medium)
CVE-2024-38364
  • github.com/dspace/dspace
DSpace Cross Site Scripting (XSS) via a deposited HTML/XML document 25 Jun 2024
  • Fix available
  • Severity - 2.6 (Low)
GHSA-94cc-xjxr-pwvf
  • Maven/org.dspace:dspace-server-webapp
DSpace Cross Site Scripting (XSS) via a deposited HTML/XML document 25 Jun 2024
  • Fix available
  • Severity - 2.6 (Low)
GHSA-8rmh-55h4-93h5
  • Maven/org.dspace:dspace-api
DSpace ItemImportService API Vulnerable to Path Traversal in Simple Archive Format Package Import 06 Aug 2022
  • Fix available
  • Severity - 7.2 (High)
GHSA-qp5m-c3m9-8q2p
  • Maven/org.dspace:dspace-jspui
JSPUI vulnerable to path traversal in submission (resumable) upload 06 Aug 2022
  • Fix available
  • Severity - 8.2 (High)