CWE-917: Expression Language Injection
The product constructs all or part of an expression language (EL) statement in a framework such as a Java Server Page (JSP) using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended EL statement before it is executed.
41 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2025-41243 — Spring Expression Language property modification using Spring Cloud Gateway Server WebFlux
- CVE-2025-3322 — Improper Neutralization of Special Elements in OnlineSuite
- CVE-2024-51466 — IBM Cognos Analytics expression language injection
- CVE-2025-11175 — DiscussionTools should use better regex
- CVE-2024-5828 — EL Injection Vulnerability in Hitachi Tuning Manager
- CVE-2026-39842 — OpenRemote is Vulnerable to Expression Injection
- CVE-2026-11561 — SSTI in Soagen Informatics' Apinizer
- CVE-2026-2587 — A critical Remote Code Execution (RCE) vulnerability was identified in the server-side template rendering mechanism used
- CVE-2026-42811 — Apache Polaris: could broaden vended GCS credentials through unescaped identifier content in access-boundary CEL conditions
- CVE-2026-40478 — Improper neutralization of specific syntax patterns for unauthorized expressions in Thymeleaf
- CVE-2026-40477 — Improper restriction of the scope of accessible objects in Thymeleaf expressions
- CVE-2024-0715 — EL Injection Vulnerability in Hitachi Global Link Manager
- CVE-2026-2586 — An authenticated Remote Code Execution (RCE) vulnerability was identified in GlassFish's Administration Console. A user
- CVE-2026-41901 — Thymeleaf: Improper recognition of unauthorized syntax patterns in sandboxed Thymeleaf expressions
- CVE-2025-41253 — Spring Cloud Gateway Webflux SpEL Injection Vulnerability Allowing Exposure of Environment Variables
- CVE-2026-65591 — n8n before 1.123.64 Sanitizer Bypass Remote Code Execution
- CVE-2026-28201 — SurrealDB Injection on Open Notebook
- CVE-2026-41705 — Spring AI's MilvusVectorStore#doDelete(List) implementation is vulnerable to filter-expression injection via unsanitized
- CVE-2026-41717 — Spring Data MongoDB - SpEL Expression Injection via Annotated Query Parameter Binding
- CVE-2026-41883 — OmniFaces: EL injection via crafted resource name in wildcard CDN mapping
Recently published
- CVE-2026-65591 — n8n before 1.123.64 Sanitizer Bypass Remote Code Execution
- CVE-2026-11561 — SSTI in Soagen Informatics' Apinizer
- CVE-2026-40985 — Data Binding Vulnerability in Spring Web Flow with Unified EL Parser
- CVE-2026-41729 — Spring Data REST SpEL Injection via Map Key in JSON Patch
- CVE-2026-41719 — Spring Data KeyValue - SpEL Injection vulnerability in SpelPropertyComparator
- CVE-2026-41717 — Spring Data MongoDB - SpEL Expression Injection via Annotated Query Parameter Binding
- CVE-2026-2586 — An authenticated Remote Code Execution (RCE) vulnerability was identified in GlassFish's Administration Console. A user
- CVE-2026-2587 — A critical Remote Code Execution (RCE) vulnerability was identified in the server-side template rendering mechanism used
- CVE-2026-31380 — Apache OFBiz: FreeMarker SSTI via Duplicate Parameter Sanitization Bypass
- CVE-2026-8759 — xiandafu beetl SpELFunction SpELFunction.java expression language injection
- CVE-2026-41901 — Thymeleaf: Improper recognition of unauthorized syntax patterns in sandboxed Thymeleaf expressions
- CVE-2026-41705 — Spring AI's MilvusVectorStore#doDelete(List) implementation is vulnerable to filter-expression injection via unsanitized
- CVE-2026-41883 — OmniFaces: EL injection via crafted resource name in wildcard CDN mapping
- CVE-2026-28201 — SurrealDB Injection on Open Notebook
- CVE-2026-42811 — Apache Polaris: could broaden vended GCS credentials through unescaped identifier content in access-boundary CEL conditions
- CVE-2026-40478 — Improper neutralization of specific syntax patterns for unauthorized expressions in Thymeleaf
- CVE-2026-40477 — Improper restriction of the scope of accessible objects in Thymeleaf expressions
- CVE-2026-39842 — OpenRemote is Vulnerable to Expression Injection
- CVE-2025-11175 — DiscussionTools should use better regex
- CVE-2025-41253 — Spring Cloud Gateway Webflux SpEL Injection Vulnerability Allowing Exposure of Environment Variables