Advisory Database
  • Advisories
  • Dependency Scanning
  1. maven
  2. ›
  3. org.dspace/dspace-api
  4. ›
  5. CVE-2026-49832

CVE-2026-49832: DSpace has possible Remote Code Execution (RCE) through Velocity Templates used by LDN

July 8, 2026

When chained with the LDN Path Traversal Attack identified in GHSA-9qm4-rh6w-pq5x, it may be possible to execute Java directly from Velocity templates using reflection. This is a very high impact vulnerability, but the attack can only be performed by a user that has DSpace Administrator privileges. Disabling LDN (see below) removes all known attack paths.

Velocity is also used for email templating, but there is no known attack path via emails templates. Nonetheless, the patches below also apply to email templates.

References

  • github.com/DSpace/DSpace/pull/12548
  • github.com/DSpace/DSpace/pull/12549
  • github.com/DSpace/DSpace/security/advisories/GHSA-9x82-rm84-c6x7
  • github.com/advisories/GHSA-9x82-rm84-c6x7
  • nvd.nist.gov/vuln/detail/CVE-2026-49832

Code Behaviors & Features

Detect and mitigate CVE-2026-49832 with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions starting from 8.0.0-rc1 before 8.4.0, all versions starting from 9.0.0-rc1 before 9.3.0, all versions starting from 10.0.0-rc1 before 10.0.0

Fixed versions

  • 8.4.0
  • 9.3.0
  • 10.0.0

Solution

Upgrade to versions 8.4.0, 9.3.0, 10.0.0 or above.

Impact 8 HIGH

CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H

Learn more about CVSS

Weakness

  • CWE-94: Improper Control of Generation of Code ('Code Injection')

Source file

maven/org.dspace/dspace-api/CVE-2026-49832.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Sat, 11 Jul 2026 12:17:32 +0000.