CVE-2026-49830Medium· 4.4▾ SunlitDSpace open source software is a repository application which provides durable access to digital resources. Prior to versions 7.6.7, 8.4, 9.3, and 10.0, when ingesting an aggregated ORE resource by URI (using the OAI-ORE Harvester), the …
▾ Sunlit zone — Low / medium · no exploitation signal
impact 24.2 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Sep 3.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
0.4%
Last analysed / modified upstream
DSpace open source software is a repository application which provides durable access to digital resources. Prior to versions 7.6.7, 8.4, 9.3, and 10.0, when ingesting an aggregated ORE resource by URI (using the OAI-ORE Harvester), the ORE Ingestion Crosswalk does not validate the URI scheme. This may allow for local file inclusion via malicious paths like file:///etc/passwd. The attacker MUST already have DSpace collection administrator privileges in order to perform the attack. This issue has been patched in versions 7.6.7, 8.4, 9.3, and 10.0.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Affected packages:
org.dspace:dspace-api <= 7.6.6org.dspace:dspace-api >= 8.0-rc1, <= 8.3org.dspace:dspace-api >= 9.0-rc1, <= 9.2org.dspace:dspace-api = 10-rc1Patched in:
org.dspace:dspace-api 7.6.7org.dspace:dspace-api 8.4org.dspace:dspace-api 9.3org.dspace:dspace-api 10.0Connected by shared product, vendor, weakness, or advisory.
CVE-2026-49832High· 8.0DSpace open source software is a repository application which provides durable access to digital resources
CVE-2026-49831Medium· 5.5DSpace open source software is a repository application which provides durable access to digital resources
CVE-2026-49833Medium· 5.5DSpace open source software is a repository application which provides durable access to digital resources
CVE-2021-45105Medium· 5.9Apache Log4j2 versions 2.0-alpha1 through 2.16.0 (excluding 2.12.3 and 2.3.1) did not protect from uncontrolled recursion from self-referential lookups
CVE-2020-3478High· 8.1A vulnerability in the REST API of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, remote attacker to overwrite certain files that should be restricted on an affected device
CVE-2020-3577High· 7.4A vulnerability in the ingress packet processing path of Cisco Firepower Threat Defense (FTD) Software for interfaces that are configured either as Inline Pair or in Passive mode could allow an unauthenticated, adjacent attacker to cause…