Threadlinqs IntelligenceStart free

Weakness · BaseCWE-917

CWE-917: Improper Neutralization of Special Elements used in an Expression Language Statement ('Expression Language Injection')

KEV-linkedBase

As of 2026-10-10, CWE-917 (Expression Language Injection) underlies 3 CVEs tracked by Threadlinqs, 2 of them in the CISA Known Exploited Vulnerabilities catalog, and is cited by 10 tracked threats.

CVEs
3Mapped to CWE-917
CISA KEV
2Exploited in the wild
Critical
3CVSS v3 critical CVEs
Threats
10Tracked campaigns citing it
Likelihood
—MITRE likelihood of exploit

Last updated:

What is CWE-917?

The product constructs all or part of an expression language (EL) statement in a framework such as a Java Server Page (JSP) using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended EL statement before it is executed.

Frameworks such as Java Server Page (JSP) allow a developer to insert executable expressions within otherwise-static content. When the developer is not aware of the executable nature of these expressions and/or does not disable them, then if an attacker can inject expressions, this could lead to code execution or other unexpected behaviors.

CWE-917 is a base-level weakness in MITRE’s Common Weakness Enumeration. Applicable platforms: Language: Java.

Source: MITRE CWE (CWE-917 definition, reproduced verbatim). Counts and linkage below are Threadlinqs data.

Consequences

  • Confidentiality — Read Application Data
  • Integrity — Execute Unauthorized Code or Commands

Source: MITRE CWE, common consequences.

How CWE-917 is exploited in the wild

Threadlinqs maps 3 CVEs to CWE-917, published between 2021-12-10 and 2026-10-05. 2 are listed in CISA’s Known Exploited Vulnerabilities catalog, the authoritative record of exploitation in the wild, and 2 are tied to ransomware campaigns. By CVSS v3 severity the set splits into 3 critical. The highest EPSS score in the set is 99.9% (CVE-2022-26134), the modelled probability of exploitation in the next 30 days. 10 tracked threats reference CWE-917 directly or through a CVE it covers; the most recent is “Evooo1Bot: Multi-Functional Mirai-Based Linux Botnet Exploiting 18 Known CVEs in Internet-Facing Devices” (2026-10-09). Affected products concentrate in Apache (1), Apache Software Foundation (1), Atlassian (1), among 4 vendors in total.

Vulnerabilities (CVEs)

All 3 CVEs mapped to CWE-917, CISA KEV first, then by CVSS score.

  • CVE-2021-44228 — CISA KEV · CVSS 10 critical · EPSS 99.9% · published 2021-12-10
  • CVE-2022-26134 — CISA KEV · CVSS 9.8 critical · EPSS 99.9% · published 2022-06-03
  • CVE-2026-104711 — CVSS 9.8 critical · EPSS 0.8% · published 2026-10-05

Affected vendors

Threat activity

10 tracked threats cite CWE-917:

Mitigations

  • Architecture and Design: Avoid adding user-controlled data into an expression interpreter when possible.
  • Implementation: If user-controlled data must be added to an expression interpreter, one or more of the following should be performed: Validate that the user input will not evaluate as an expression Encode the user input in a way that ensures it is not evaluated as an expression
  • System Configuration, Operation: The framework or tooling might allow the developer to disable or deactivate the processing of EL expressions, such as setting the isELIgnored attribute for a JSP page to "true".

Source: MITRE CWE, potential mitigations.

Detection methods (MITRE CWE)

  • Automated Static Analysis (effectiveness: High): Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without having to execute it. Typically, this is done by building a model of data flow and control flow, then searching for potentially-vulnerable patterns that connect "sources" (origins of input) with "sinks" (destinations where the data interacts with external components, a lower layer such as the OS, etc.)

Source: MITRE CWE, detection methods. Threadlinqs detection rules for the threats above are Blue tier and higher.