VulnSea

CWE-917

CVEs classified under CWE-917, newest first.

14 CVEsRSS

CVE-2026-91145High· 7.1PoC
1w ago

Activiti through 7.1.0.M6 fails to validate hash-brace deferred expressions in process variables, allowing attackers to bypass expression filtering

Activiti through 7.1.0.M6 fails to validate hash-brace deferred expressions in process variables, allowing attackers to bypass expression filtering. Attackers can inject expressions beginning with #{ that are stored and later evaluated i…

MidnightActiviti · ActivitiEPSS 0.24%via NVD
CVE-2026-88030High· 8.3
1w ago

Improper neutralization of special elements in data query logic in the GridFS component of the MongoDB Ruby Driver can cause a caller-supplied structured file identifier to be interpreted as a query condition rather than as a literal ide…

Improper neutralization of special elements in data query logic in the GridFS component of the MongoDB Ruby Driver can cause a caller-supplied structured file identifier to be interpreted as a query condition rather than as a literal ide…

TwilightMongoDB · Ruby DriverEPSS 0.26%via NVD
GHSA-m7jc-p4hf-xhwqHigh
2mo ago

Duplicate Advisory: Legacy Expression Evaluator Sanitizer Bypass Leads to Authenticated Code Execution

Duplicate Advisory: Legacy Expression Evaluator Sanitizer Bypass Leads to Authenticated Code Execution

Twilightn8n · n8nvia GHSA
CVE-2026-65591HighPoC
2mo ago

n8n: Legacy Expression Evaluator Sanitizer Bypass Leads to Authenticated Code Execution

n8n: Legacy Expression Evaluator Sanitizer Bypass Leads to Authenticated Code Execution

Midnightn8n · n8nEPSS 0.48%via GHSA
CVE-2026-40985Medium· 6.4
3mo ago

Applications that configure the WebFlowELExpressionParser are vulnerable to the use of malicious Unified EL expressions. Affected versions: Spring Web Flow 4.0.0; 3.0.0 through 3.0.1; 2.5.0 through 2.5.1.

Applications that configure the WebFlowELExpressionParser are vulnerable to the use of malicious Unified EL expressions. Affected versions: Spring Web Flow 4.0.0; 3.0.0 through 3.0.1; 2.5.0 through 2.5.1.

Sunlitbroadcom · spring_web_flowEPSS 0.23%via NVD
CVE-2026-41729High· 8.1PoC
3mo ago

Spring Data REST is vulnerable to SpEL expression injection through map-typed properties when processing JSON Patch (application/json-patch+json) requests

Spring Data REST is vulnerable to SpEL expression injection through map-typed properties when processing JSON Patch (application/json-patch+json) requests. When a persistent entity exposes a Map-typed property, the JSON Pointer path segm…

Midnightvmware · spring_data_restEPSS 0.39%via NVD
CVE-2026-41719Medium· 6.4
3mo ago

A SpEL Injection vulnerability exists in the Spring Data KeyValue if unsanitized user input is passed as Sort into a repository query method that delegates evaluation to the SpelPropertyComparator. Affected versions: Spring Data KeyValu…

A SpEL Injection vulnerability exists in the Spring Data KeyValue if unsanitized user input is passed as Sort into a repository query method that delegates evaluation to the SpelPropertyComparator. Affected versions: Spring Data KeyValu…

Sunlitbroadcom · spring_data_keyvalueEPSS 0.21%via NVD
CVE-2026-41717High· 8.1
3mo ago

Spring Data MongoDB contains a SpEL (Spring Expression Language) expression injection vulnerability

Spring Data MongoDB contains a SpEL (Spring Expression Language) expression injection vulnerability. The issue occurs during parameter binding when a user-defined repository query method is annotated with @Query and utilizes a capture-al…

Twilightvmware · spring_data_mongodbEPSS 0.33%via NVD
CVE-2026-2587Critical· 9.6PoC
4mo ago

A critical Remote Code Execution (RCE) vulnerability was identified in the server-side template rendering mechanism used by the Glassfish gadget handler

A critical Remote Code Execution (RCE) vulnerability was identified in the server-side template rendering mechanism used by the Glassfish gadget handler. The application processes .xml files and evaluates user-supplied values within a co…

AbyssalEPSS 0.65%via NVD
CVE-2026-2586Critical· 9.1PoC
4mo ago

An authenticated Remote Code Execution (RCE) vulnerability was identified in GlassFish's Administration Console

An authenticated Remote Code Execution (RCE) vulnerability was identified in GlassFish's Administration Console. A user with access to the panel can send crafted requests that allow the execution of arbitrary operating system commands wi…

AbyssalEPSS 0.84%via NVD
CVE-2026-40478Critical· 9.0
5mo ago

Thymeleaf is a server-side Java template engine for web and standalone environments

Thymeleaf is a server-side Java template engine for web and standalone environments. Versions 3.1.3.RELEASE and prior contain a security bypass vulnerability in the the expression execution mechanisms. Although the library provides mecha…

Midnightthymeleaf · thymeleafEPSS 1.1%via NVD
CVE-2026-40477Critical· 9.0PoC
5mo ago

Thymeleaf is a server-side Java template engine for web and standalone environments

Thymeleaf is a server-side Java template engine for web and standalone environments. Versions 3.1.3.RELEASE and prior contain a security bypass vulnerability in the expression execution mechanisms. Although the library provides mechanism…

Abyssalthymeleaf · thymeleafEPSS 0.85%via NVD
CVE-2026-33938High· 8.1
5mo ago

Handlebars provides the power necessary to let users build semantic templates

Handlebars provides the power necessary to let users build semantic templates. In versions 4.0.0 through 4.7.8, the `@partial-block` special variable is stored in the template data context and is reachable and mutable from within a templ…

Twilighthandlebarsjs · handlebarsEPSS 0.71%via NVD
CVE-2026-24737High· 8.1
7mo ago

jsPDF is a library to generate PDFs in JavaScript

jsPDF is a library to generate PDFs in JavaScript. Prior to 4.1.0, user control of properties and methods of the Acroform module allows users to inject arbitrary PDF objects, such as JavaScript actions. If given the possibility to pass u…

Twilightparall · jspdfEPSS 0.55%via NVD
CWE-917 vulnerabilities (CVEs) · VulnSea