VYPR
High severity7.9NVD Advisory· Published Nov 25, 2020· Updated Jun 17, 2026

CVE-2020-26238

CVE-2020-26238

Description

Cron-utils is a Java library to parse, validate, migrate crons as well as get human readable descriptions for them. In cron-utils before version 9.1.3, a template Injection vulnerability is present. This enables attackers to inject arbitrary Java EL expressions, leading to unauthenticated Remote Code Execution (RCE) vulnerability. Only projects using the @Cron annotation to validate untrusted Cron expressions are affected. This issue was patched in version 9.1.3.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
com.cronutils:cron-utilsMaven
< 9.1.39.1.3

Affected products

3

Patches

Vulnerability mechanics

References

25

News mentions

0

No linked articles in our index yet.