Critical severity9.8NVD Advisory· Published Dec 19, 2019· Updated Jun 17, 2026
CVE-2019-19899
CVE-2019-19899
Description
Pebble Templates 3.1.2 allows attackers to bypass a protection mechanism (intended to block access to instances of java.lang.Class) because getClass is accessible via the public static java.lang.Class java.lang.Class.forName(java.lang.Module,java.lang.String) signature.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
io.pebbletemplates:pebble-projectMaven | < 3.1.4 | 3.1.4 |
Affected products
3- cpe:2.3:a:pebbletemplates:pebble_templates:3.1.2:*:*:*:*:*:*:*
- Pebble Templates/Pebble Templatesdescription
Patches
Vulnerability mechanics
References
5- github.com/PebbleTemplates/pebble/issues/493nvdExploitThird Party AdvisoryWEB
- github.com/advisories/GHSA-83m8-7hj8-ff5wghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2019-19899ghsaADVISORY
- github.com/PebbleTemplates/pebble/pull/511ghsaWEB
- research.securitum.com/server-side-template-injection-on-the-example-of-pebbleghsaWEB
News mentions
0No linked articles in our index yet.