Spring Data Rest vulnerabilities
4 known vulnerabilities affecting spring/spring_data_rest.
Total CVEs
4
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH2MEDIUM2
Vulnerabilities
Page 1 of 1
CVE-2026-41729P3HIGHCVSS 8.1≥ 3.7.0, < 3.7.20≥ 4.3.0, < 4.3.17+3 more2026-06-10
CVE-2026-41729 [HIGH] CWE-917 CVE-2026-41729: Spring Data REST is vulnerable to SpEL expression injection through map-typed properties when proces
Spring Data REST is vulnerable to SpEL expression injection through map-typed properties when processing JSON Patch (application/json-patch+json) requests. When a persistent entity exposes a Map-typed property, the JSON Pointer path segment used as the map key is embedded directly into a SpEL expression without sanitization or validation.
Affected ve
nvd
CVE-2026-41728P3HIGHCVSS 7.5≥ 3.7.0, < 3.7.20≥ 4.3.0, < 4.3.17+3 more2026-06-10
CVE-2026-41728 [HIGH] CWE-284 CVE-2026-41728: Spring Data REST's JSON Patch (application/json-patch+json) implementation does not apply the write-
Spring Data REST's JSON Patch (application/json-patch+json) implementation does not apply the write-access filter to intermediate path segments when resolving a multi-segment JSON Pointer.
Affected versions:
Spring Data REST 3.7.0 through 3.7.19; 4.3.0 through 4.3.16; 4.4.0 through 4.4.14; 4.5.0 through 4.5.11; 5.0.0 through 5.0.5.
nvd
CVE-2026-41837P4MEDIUMCVSS 5.3≥ 3.7.0, < 3.7.20≥ 4.3.0, < 4.3.17+3 more2026-06-10
CVE-2026-41837 [MEDIUM] CWE-284 CVE-2026-41837: Spring Data REST's Querydsl integration accepts arbitrary persistent property paths as request-param
Spring Data REST's Querydsl integration accepts arbitrary persistent property paths as request-parameter filter keys and does not consider Jackson customizations before handing them to Querydsl.
Affected versions:
Spring Data REST 3.7.0 through 3.7.19; 4.3.0 through 4.3.16; 4.4.0 through 4.4.14; 4.5.0 through 4.5.11; 5.0.0 through 5.0.5.
nvd
CVE-2026-41730P4MEDIUMCVSS 5.3≥ 3.7.0, < 3.7.20≥ 4.3.0, < 4.3.17+3 more2026-06-10
CVE-2026-41730 [MEDIUM] CWE-209 CVE-2026-41730: Spring Data REST serializes the full exception cause chain into HTTP error response bodies, potentia
Spring Data REST serializes the full exception cause chain into HTTP error response bodies, potentially exposing persistence-layer internals to HTTP clients.
Affected versions:
Spring Data REST 3.7.0 through 3.7.19; 4.3.0 through 4.3.16; 4.4.0 through 4.4.14; 4.5.0 through 4.5.11; 5.0.0 through 5.0.5.
nvd