org.dspace:dspace-api vulnerabilities
CVEs whose affected-version data names the org.dspace:dspace-api package (maven). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
4 CVEsRSS
CVE-2026-49832High· 8.0DSpace open source software is a repository application which provides durable access to digital resources
DSpace open source software is a repository application which provides durable access to digital resources. From versions 8.0-rc1 to before 8.4, versions 9.0-rc1 to before 9.3, and version 10-rc1, Remote Code Execution (RCE) is possible …
CVE-2026-49831Medium· 5.5DSpace open source software is a repository application which provides durable access to digital resources
DSpace open source software is a repository application which provides durable access to digital resources. Prior to versions 7.6.7, 8.4, 9.3, and 10.0, the Curation Task feature allows an output path to be used by the reporter (-r param…
CVE-2026-49830Medium· 4.4DSpace open source software is a repository application which provides durable access to digital resources
DSpace open source software is a repository application which provides durable access to digital resources. Prior to versions 7.6.7, 8.4, 9.3, and 10.0, when ingesting an aggregated ORE resource by URI (using the OAI-ORE Harvester), the …
CVE-2026-49833Medium· 5.5DSpace open source software is a repository application which provides durable access to digital resources
DSpace open source software is a repository application which provides durable access to digital resources. From versions 8.0-rc1 to before 8.4, 9.0-rc1 to before 9.3, and 10-rc1 to before 10.0, a path traversal vulnerability is possible…