Your RSA-2048 keys break in 2030. Find every one of them before attackers do.
☕
☕ Maven
Not in CISA KEV
MEDIUM severity

CVE-2021-28170 — el-ri

MEDIUMFix: eclipse-ee4j/el-ri#160

CVE-2021-28170 is a medium-severity (CVSS 5.3) Improper Input Validation vulnerability in com.sun.el:el-ri. 2 public exploit references exist, so weaponization risk is real. A fix is available for com.sun.el:el-ri — see the affected versions and patch details below.

Improper Input Validation in Jakarta Expression Language

Also known asGHSA-v6w3-2prq-h95f
Published
Updated
Affected
3 pkgs
Patched
2 / 3
Exploits
2 known
Exploitation data as of Oct 10, 2026 · OSV.dev, NVD, FIRST.org (EPSS)

EPSS Exploitation Probability

via FIRST.org ↗
2.1%probability of exploitation in next 30 days
Lower Risk+2.02%
Lower risk than most CVEs81th percentile — riskier than 81% of all scored CVEsHighest risk
0.00%0.91%1.82%2.74%0.1%0.1%2.1%Apr 26May 26Oct 26

Probability of exploitation in the next 30 days, from FIRST.org EPSS.

How urgent is this, really

CVE-2021-28170 by exploitation likelihood (EPSS) against impact (CVSS). Outside the shaded patch-first corner.

Where this sits among everything scored

Of 385,386 CVEs with a current EPSS score, this one falls in the < 10% band (highlighted). Counts from FIRST.org, log-scaled.

Real-World Exposure

3 pkgs affected
☕com.sun.el:el-ri☕org.glassfish:jakarta.el☕org.glassfish:javax.el

Real-time download stats are indexed for npm and PyPI packages. This vulnerability affects Maven packages — download data is not available via public APIs for these ecosystems.

Description

In the Jakarta Expression Language implementation 3.0.3 and earlier, a bug in the ELParserTokenManager enables invalid EL expressions to be evaluated as if they were valid.

Affected Packages

3 total 2 fixed
EcosystemPackageVulnerable rangeFix
☕Mavencom.sun.el:el-riall versions3.0.4com.sun.el:el-ri:3.0.4
☕Mavenorg.glassfish:jakarta.elall versions3.0.4org.glassfish:jakarta.el:3.0.4
☕Mavenorg.glassfish:javax.elall versionsNo fix

Affected Products

4 products · 4 configurations
Application
jakarta expression languageeclipse
≤ 3.0.3
range
Application
communications cloud native core policyoracle
1 version
1.14.0
Application
weblogic serveroracle
1 version
14.1.1.0.0
Application
quarkusquarkus
< 2.3.0
range
Exploits & PoCs
2

Research use only. For defensive security, authorized penetration testing, and academic research only. Never execute exploit code against systems without explicit written authorization.

Detection & mitigation playbook

Open-source dependency
  1. Detect

    Scan your dependency tree (package-lock.json, pnpm-lock.yaml, requirements.txt, go.sum, etc.) for com.sun.el:el-ri, including transitive dependencies — a direct dependency you never call can still pull in a vulnerable version.

  2. Fix

    Update com.sun.el:el-ri to 3.0.4 or later, then make sure no transitive (indirect) dependency still pins the vulnerable range — O3 confirms CVE-2021-28170 is resolved across your whole dependency graph.

  3. Workarounds

    Stop passing untrusted input into the interpreter or shell: call the affected binary with an argument array rather than a composed command string, reject anything outside a strict allowlist of expected values, and run the component under an account that cannot reach beyond the work it legitimately does.

Fixing This On Your OS

If you run this on a Linux distribution, patch through your package manager against the distro's own security advisory below — it tracks the exact backported fix for your release, which can ship on a different timeline (and sometimes a different severity) than the upstream project.

Red HatModerate
ProductFixed inAdvisory
EAP 7.3.9 releasejakarta.elRHSA-2021:3471
Red Hat build of Quarkus 2.2.5jakarta.elRHSA-2022:0589
Red Hat EAP-XP 2.0.0 via EAP 7.3.x basejakarta.elRHSA-2021:3516
Red Hat Fuse 7.10jakarta.elRHSA-2021:5134
Red Hat JBoss Enterprise Application Platformorg.glassfish/jakarta.el:3.0.3.redhat-00006RHSA-2021:3660
Red Hat JBoss Enterprise Application Platform 7.1 EUS for RHEL 7eap7-glassfish-el-0:3.0.1-4.b08_redhat_00005.1.ep7.el7RHSA-2025:9582
Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 6eap7-apache-commons-io-0:2.10.0-1.redhat_00001.1.el6eapRHSA-2021:3466
Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 7eap7-apache-commons-io-0:2.10.0-1.redhat_00001.1.el7eapRHSA-2021:3467

Frequently Asked Questions

In the Jakarta Expression Language implementation 3.0.3 and earlier, a bug in the ELParserTokenManager enables invalid EL expressions to be evaluated as if they were valid.
O3 Security · Impact-Aware SCA

Is CVE-2021-28170 in your dependencies?

Find it across Maven, including transitive dependencies.

CVE-2021-28170: el-ri — Fixed in 3.0.4