← Back

CVE-2026-41719

nvd nist
Published: Jun 10, 2026Modified: Jul 17, 2026

JSON object

Loading...
6.4
Vector
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:L/A:L
Exploitability: 1.6 / Impact: 4.7
Source: security@vmware.com (Secondary)

Description

A SpEL Injection vulnerability exists in the Spring Data KeyValue if unsanitized user input is passed as Sort into a repository query method that delegates evaluation to the SpelPropertyComparator. Affected versions: Spring Data KeyValue / Spring Data Redis 4.0.0 through 4.0.5; 3.5.0 through 3.5.11; 3.4.0 through 3.4.14; 3.3.0 through 3.3.16; 3.2.0 through 3.2.15; 3.1.0 through 3.1.14; 3.0.0 through 3.0.15; 2.7.0 through 2.7.19.

Affected (16)

2 products
Spring Data Keyvalue
Spring Data Redis
Configuration A
8 vulnerable
Vulnerable SoftwareAffected Versions
Broadcom
From 2.7.0 to 2.7.20
From 3.0.0 to 3.0.16
From 3.1.0 to 3.1.15
From 3.2.0 to 3.2.16
From 3.3.0 to 3.3.17
From 3.4.0 to 3.4.15
From 3.5.0 to 3.5.11.1
From 4.0.0 to 4.0.5.1
Configuration B
8 vulnerable
Vulnerable SoftwareAffected Versions
Broadcom
From 2.7.0 to 2.7.20
From 3.0.0 to 3.0.16
From 3.1.0 to 3.1.15
From 3.2.0 to 3.2.16
From 3.3.0 to 3.3.17
From 3.4.0 to 3.4.15
From 3.5.0 to 3.5.11.1
From 4.0.0 to 4.0.5.1

References (1)

Source: security@vmware.com
Vendor Advisory

Timeline

No history available yet.