VYPR

Spring Data KeyValue

by Spring Projects

CVEs (1)

  • CVE-2026-41719MedJun 10, 2026
    risk 0.42cvss 6.4epss 0.00

    A SpEL Injection vulnerability exists in the Spring Data KeyValue if unsanitized user input is passed as Sort into a repository query method that delegates evaluation to the SpelPropertyComparator. Affected versions: Spring Data KeyValue / Spring Data Redis 4.0.0 through 4.0.5;…