CVE-2023-51079: Mvel
Medium severity, CVSS 5.3. EPSS: 0.7% chance of exploitation in the next 30 days.
A long execution time can occur in the ParseTools.subCompileExpression method in MVEL 2.5.0.Final because of many Java class lookups. NOTE: the vendor disputes this because "the only thing that you could expect is that the parser will take a crazy amount of time to complete its task."
Affected products
- Mvel Mvel: version 2.5.0 only
Published 2023-12-27. Last modified 2026-06-17.