Your RSA-2048 keys break in 2030. Find every one of them before attackers do.
☕
☕ Maven
Not in CISA KEV
HIGH severity

CVE-2020-13936 — velocity-engine-parent

HIGH

CVE-2020-13936 is a high-severity (CVSS 8.8) vulnerability in org.apache.velocity:velocity-engine-parent. EPSS puts its 30-day exploitation probability at 22.7% (98th percentile). A fix is available for org.apache.velocity:velocity-engine-parent — see the affected versions and patch details below.

Sandbox Bypass in Apache Velocity Engine

Also known asGHSA-59j4-wjwp-mw9m
Published
Updated
Affected
2 pkgs
Patched
1 / 2
Exploits
None indexed
Exploitation data as of Oct 10, 2026 · OSV.dev, NVD, FIRST.org (EPSS)

EPSS Exploitation Probability

via FIRST.org ↗
22.7%probability of exploitation in next 30 days
Moderate Risk0.00%
Lower risk than most CVEs98th percentile — riskier than 98% of all scored CVEsHighest risk
14.5%17.9%21.2%24.6%16.4%22.7%Apr 26Aug 26Oct 26

Probability of exploitation in the next 30 days, from FIRST.org EPSS.

How urgent is this, really

CVE-2020-13936 by exploitation likelihood (EPSS) against impact (CVSS). Outside the shaded patch-first corner.

Where this sits among everything scored

Of 385,738 CVEs with a current EPSS score, this one falls in the 10–50% band (highlighted). Counts from FIRST.org, log-scaled.

Real-World Exposure

2 pkgs affected
☕org.apache.velocity:velocity-engine-parent☕org.apache.velocity:velocity

Real-time download stats are indexed for npm and PyPI packages. This vulnerability affects Maven packages — download data is not available via public APIs for these ecosystems.

Description

An attacker that is able to modify Velocity templates may execute arbitrary Java code or run arbitrary system commands with the same privileges as the account running the Servlet container. This applies to applications that allow untrusted users to upload/modify velocity templates running Apache Velocity Engine versions up to 2.2.

Affected Packages

2 total 1 fixed
EcosystemPackageVulnerable rangeFix
☕Mavenorg.apache.velocity:velocity-engine-parentall versions2.3org.apache.velocity:velocity-engine-parent:2.3
☕Mavenorg.apache.velocity:velocityall versionsNo fix

Affected Products

16 products · 28 configurations
Application
velocity engineapache
< 2.3
range
Application
wss4japache
1 version
2.3.1
OS
debian linuxdebian
1 version
9.0
Application
banking deposits and lines of credit servicingoracle
1 version
2.12.0
Application
banking enterprise default managementoracle
≥ 2.3.0 && ≤ 2.4.1
4 versions
2.6.22.7.12.10.02.12.0
Application
banking loans servicingoracle
1 version
2.12.0

Detection & mitigation playbook

Open-source dependency
  1. Detect

    Scan your dependency tree (package-lock.json, pnpm-lock.yaml, requirements.txt, go.sum, etc.) for org.apache.velocity:velocity-engine-parent, including transitive dependencies — a direct dependency you never call can still pull in a vulnerable version.

  2. Fix

    Update org.apache.velocity:velocity-engine-parent to 2.3 or later, then make sure no transitive (indirect) dependency still pins the vulnerable range — O3 confirms CVE-2020-13936 is resolved across your whole dependency graph.

  3. Workarounds

    If you can't upgrade right away: gate or disable the affected feature, validate untrusted input at the boundary, and avoid passing attacker-controlled data into the vulnerable path. O3's runtime protection blocks exploitation in production as an interim safeguard until the upgrade lands.

Fixing This On Your OS

If you run this on a Linux distribution, patch through your package manager against the distro's own security advisory below — it tracks the exact backported fix for your release, which can ship on a different timeline (and sometimes a different severity) than the upstream project.

Red HatImportant

OpenShift Container Platform (OCP) openshift-logging/elasticsearch6-rhel8 container does contain a vulnerable version of velocity. The references to the library only occur in the x-pack component which is an enterprise-only feature of Elasticsearch - hence it has been marked as wontfix as this time and may be fixed in…

ProductFixed inAdvisory
Red Hat EAP-XP 2.0.0 via EAP 7.3.x basevelocityRHSA-2021:2755
Red Hat EAP-XP via EAP 7.3.x basevelocityRHSA-2021:2210
Red Hat Fuse 7.9velocityRHSA-2021:3140
Red Hat IntegrationvelocityRHSA-2021:4918
Red Hat Integration Camel Quarkus 2see advisoryRHSA-2021:4767
Red Hat JBoss Enterprise Application Platformorg.apache.velocity/velocity-engine-core:2.3.0.redhat-00001RHSA-2021:3660
Red Hat JBoss Enterprise Application Platform 7velocityRHSA-2021:2051
Red Hat JBoss Enterprise Application Platform 7.1 EUS for RHEL 7eap7-resteasy-0:3.0.27-1.Final_redhat_00001.1.ep7.el7RHSA-2025:1746

Frequently Asked Questions

An attacker that is able to modify Velocity templates may execute arbitrary Java code or run arbitrary system commands with the same privileges as the account running the Servlet container. This applies to applications that allow untrusted users to upload/modify velocity templates running Apache Velocity Engine versions up to 2.2.
O3 Security · Impact-Aware SCA

Is CVE-2020-13936 in your dependencies?

Find it across Maven, including transitive dependencies.

CVE-2020-13936: velocity-engine-parent — Fixed in 2.3