GHSA-29wv-cv7p-xjc2

Suggest an improvement
Source
https://github.com/advisories/GHSA-29wv-cv7p-xjc2
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/05/GHSA-29wv-cv7p-xjc2/GHSA-29wv-cv7p-xjc2.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-29wv-cv7p-xjc2
Aliases
Published
2026-05-19T15:31:35Z
Modified
2026-09-10T03:50:45Z
Severity
  • 9.6 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H CVSS Calculator
Summary
GlassFish's gadget handler is vulnerable to RCE
Details

A critical Remote Code Execution (RCE) vulnerability was identified in the server-side template rendering mechanism used by the Glassfish gadget handler. The application processes .xml files and evaluates user-supplied values within a context where Expression Language (EL) “expressions” are processed without proper sanitization or escaping. By injecting expressions such as #{7*7}, the server returns 49, confirming server-side EL evaluation. This issue allows a remote attacker to fully compromise the underlying host, enabling capabilities as reading/modifying data, executing arbitrary commands, persistence, and lateral movement.

Database specific
{
    "cwe_ids":  [
        "CWE-917"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2026-06-04T19:21:21Z",
    "nvd_published_at":  "2026-05-19T15:16:28Z",
    "severity":  "CRITICAL"
}
References

Affected packages

Maven / org.glassfish.main.admingui:admingui

Package

Name
org.glassfish.main.admingui:admingui
View open source insights on deps.dev
Purl
pkg:maven/org.glassfish.main.admingui/admingui

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
8.0.2

Affected versions

3.*
3.1.2
3.1.2.2
4.*
4.0-b33
4.0-b72
4.0-b90
4.0
4.1
4.1.1
4.1.2
5.*
5.0
5.0.1
5.1.0-RC1
5.1.0-RC2
5.1.0
6.*
6.0.0-M1
6.0.0-RC1
6.0.0-RC2
6.0.0-RC3
6.0.0-RC4
6.0.0
6.1.0
6.2.0
6.2.1
6.2.2
6.2.3
6.2.4
6.2.5
7.*
7.0.0-M1
7.0.0-M2
7.0.0-M3
7.0.0-M4
7.0.0-M10
7.0.0
7.0.1
7.0.2
7.0.3
7.0.4
7.0.5
7.0.6
7.0.7
7.0.8
7.0.9
7.0.10
7.0.11
7.0.12
7.0.13
7.0.14
7.0.15
7.0.16
7.0.17
7.0.18
7.0.19
7.0.20
7.0.21
7.0.22
7.0.23
7.0.24
7.0.25
7.0.26
7.1.0-M1
7.1.0
7.1.1
8.*
8.0.0-M1
8.0.0-M2
8.0.0-M3
8.0.0-M5
8.0.0-M6
8.0.0-M7
8.0.0-M8
8.0.0-M9
8.0.0-M10
8.0.0-M11
8.0.0-M12
8.0.0-M13
8.0.0-M14
8.0.0-M15
8.0.0
8.0.0-DONTPUBLISH
8.0.0-JDK17-M5
8.0.0-JDK17-M6
8.0.0-JDK17-M7
8.0.0-JDK17-M9
8.0.0-JDK17-M10
8.0.0-JDK17-M12
8.0.1

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/05/GHSA-29wv-cv7p-xjc2/GHSA-29wv-cv7p-xjc2.json"

Maven / org.glassfish.jsftemplating:jsftemplating

Package

Name
org.glassfish.jsftemplating:jsftemplating
View open source insights on deps.dev
Purl
pkg:maven/org.glassfish.jsftemplating/jsftemplating

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
4.2.0

Affected versions

1.*
1.2.0-1
1.2.1
1.2.2
1.2.3
3.*
3.0.0
4.*
4.0.0
4.0.1
4.0.2
4.0.3
4.0.4
4.0.5
4.1.0-M1
4.1.0

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/05/GHSA-29wv-cv7p-xjc2/GHSA-29wv-cv7p-xjc2.json"