8 Total advisories
8 Vulnerabilities
0 Malware
Dependency scanning
Check whether org.dspace:dspace-api is in your codebase
Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.
Vulnerabilities
MEDIUM 5.5
CVE-2026-49833
DSpace: Path Traversal is possible through LDN message generation
MEDIUM 4.4
CVE-2026-49830
DSpace: ORE resource URI does not validate scheme for non-web resources
HIGH 8.0
CVE-2026-49832
DSpace has possible Remote Code Execution (RCE) through Velocity Templates used by LDN
MEDIUM 5.5
CVE-2026-49831
DSpace has a possible Path Traversal Vulnerability in its Curation Task Reporter output path
HIGH 7.2
CVE-2021-41189
Communities and collections administrators can escalate their privilege up to system administrator
MEDIUM 5.2
CVE-2025-53622
DSpace is vulnerable to Path Traversal attacks when importing packages using Simple Archive Format
MEDIUM 6.9
CVE-2025-53621
DSpace is vulnerable to XML External Entity injection during archive imports
HIGH 7.2
CVE-2022-31195
DSpace ItemImportService API Vulnerable to Path Traversal in Simple Archive Format Package Import
Browse more Maven advisories
Learn What is SAST?
Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →
Ready to move
Start Securing
Free, no credit card | First findings in minutes