VYPR

Maven package

org.springframework.data/spring-data-keyvalue

pkg:maven/org.springframework.data/spring-data-keyvalue

Vulnerabilities (1)

  • CVE-2026-41719MedJun 10, 2026
    affected >= 4.0.0, < 4.0.6fixed 4.0.6

    A SpEL Injection vulnerability exists in the Spring Data KeyValue if unsanitized user input is passed as Sort into a repository query method that delegates evaluation to the SpelPropertyComparator. Affected versions: Spring Data KeyValue / Spring Data Redis 4.0.0 through 4.0.5;