CVE-2026-49832
moderateRCE via Velocity Template injection in DSpace COAR Notify/LDN message handling
CVE-2026-49832 is a code injection flaw (CWE-94) in DSpace, the open-source institutional repository platform: Velocity Templates used by DSpace to render COAR Notify/LDN (Linked Data Notifications) messages can be abused to achieve Remote Code Execution on the server. It is triggered when DSpace processes COAR Notify/LDN message content through these templates; the CVSS vector (AV:N/AC:H/PR:H/UI:N/S:C) indicates the attack is network-reachable but requires high-level privileges (e.g., administrator-level access to the repository) and conditions outside the attacker's full control. A successful attacker gains remote code execution with high confidentiality, integrity and availability impact, and the Changed Scope metric suggests compromise can extend beyond the vulnerable component to the wider host. All deployments running DSpace 8.0-rc1 up to (but not including) 8.4, 9.0-rc1 up to (but not including) 9.3, or 10-rc1 are affected; fixes are available in DSpace 8.4, 9.3, and 10.0. No public proof-of-concept, KEV listing, or in-the-wild exploitation is known; EPSS assigns only a ~0.5% probability of exploitation in the next 30 days.
What to do: Upgrade affected instances to DSpace 8.4, 9.3, or 10.0 depending on your release line. Until patching, restrict or disable inbound COAR Notify/LDN message processing, limit who can configure notification templates or submit LDN messages, and audit administrator accounts given the high-privilege requirement (PR:H) in the CVSS vector. Confirm whether your deployment actually uses COAR Notify/LDN support, since sites that do not process these messages are unlikely to hit the vulnerable code path.
| DSpace (open source project) DSpace | 8.0-rc1 through all versions before 8.4 (8.x < 8.4) |
| DSpace (open source project) DSpace | 9.0-rc1 through all versions before 9.3 (9.x < 9.3) |
| DSpace (open source project) DSpace | 10-rc1 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
DSpace open source software is a repository application which provides durable access to digital resources. From versions 8.0-rc1 to before 8.4, versions 9.0-rc1 to before 9.3, and version 10-rc1, Remote Code Execution (RCE) is possible via Velocity Templates used by DSpace for COAR Notify/LDN messages. This issue has been patched in versions 8.4, 9.3, and 10.0.
- Weakness
- CWE-94
- Vector
- CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.