CVE-2023-51079: Mvel

Medium severity, CVSS 5.3. EPSS: 0.7% chance of exploitation in the next 30 days.

A long execution time can occur in the ParseTools.subCompileExpression method in MVEL 2.5.0.Final because of many Java class lookups. NOTE: the vendor disputes this because "the only thing that you could expect is that the parser will take a crazy amount of time to complete its task."

Affected products

  • Mvel Mvel: version 2.5.0 only

Published 2023-12-27. Last modified 2026-06-17.