ZeroHour

CVE-2026-49832

moderate

RCE via Velocity Template injection in DSpace COAR Notify/LDN message handling

CVSS 3.1
8.0 high
EPSS
<1%p44
Published
()
Modified
AI analysis

CVE-2026-49832 is a code injection flaw (CWE-94) in DSpace, the open-source institutional repository platform: Velocity Templates used by DSpace to render COAR Notify/LDN (Linked Data Notifications) messages can be abused to achieve Remote Code Execution on the server. It is triggered when DSpace processes COAR Notify/LDN message content through these templates; the CVSS vector (AV:N/AC:H/PR:H/UI:N/S:C) indicates the attack is network-reachable but requires high-level privileges (e.g., administrator-level access to the repository) and conditions outside the attacker's full control. A successful attacker gains remote code execution with high confidentiality, integrity and availability impact, and the Changed Scope metric suggests compromise can extend beyond the vulnerable component to the wider host. All deployments running DSpace 8.0-rc1 up to (but not including) 8.4, 9.0-rc1 up to (but not including) 9.3, or 10-rc1 are affected; fixes are available in DSpace 8.4, 9.3, and 10.0. No public proof-of-concept, KEV listing, or in-the-wild exploitation is known; EPSS assigns only a ~0.5% probability of exploitation in the next 30 days.

What to do: Upgrade affected instances to DSpace 8.4, 9.3, or 10.0 depending on your release line. Until patching, restrict or disable inbound COAR Notify/LDN message processing, limit who can configure notification templates or submit LDN messages, and audit administrator accounts given the high-privilege requirement (PR:H) in the CVSS vector. Confirm whether your deployment actually uses COAR Notify/LDN support, since sites that do not process these messages are unlikely to hit the vulnerable code path.

Affected
DSpace (open source project) DSpace8.0-rc1 through all versions before 8.4 (8.x < 8.4)
DSpace (open source project) DSpace9.0-rc1 through all versions before 9.3 (9.x < 9.3)
DSpace (open source project) DSpace10-rc1
Estimated exposure
moderate≈1,000–3,000 repository installations worldwide (a subset of the several thousand DSpace deployments running affected 8.x/9.x/10-rc versions, likely fewer… — DSpace is one of the most widely used open-source institutional repository platforms, commonly cited at over 2,000 academic and library deployments, but only sites on the recent 8.x/9.x/10-rc release lines that exercise the COAR Notify/LDN…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

DSpace open source software is a repository application which provides durable access to digital resources. From versions 8.0-rc1 to before 8.4, versions 9.0-rc1 to before 9.3, and version 10-rc1, Remote Code Execution (RCE) is possible via Velocity Templates used by DSpace for COAR Notify/LDN messages. This issue has been patched in versions 8.4, 9.3, and 10.0.

Weakness
CWE-94
Vector
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.