CVE-2026-41719Medium· 6.4▾ SunlitA SpEL Injection vulnerability exists in the Spring Data KeyValue if unsanitized user input is passed as Sort into a repository query method that delegates evaluation to the SpelPropertyComparator. Affected versions: Spring Data KeyValu…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 35.2 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 17.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.2%
0.2% → 0.2%
A SpEL Injection vulnerability exists in the Spring Data KeyValue if unsanitized user input is passed as Sort into a repository query method that delegates evaluation to the SpelPropertyComparator.
Affected versions: Spring Data KeyValue / Spring Data Redis 4.0.0 through 4.0.5; 3.5.0 through 3.5.11; 3.4.0 through 3.4.14; 3.3.0 through 3.3.16; 3.2.0 through 3.2.15; 3.1.0 through 3.1.14; 3.0.0 through 3.0.15; 2.7.0 through 2.7.19.
spring_data_keyvalue >= 2.7.0, < 2.7.20spring_data_keyvalue >= 3.0.0, < 3.0.16spring_data_keyvalue >= 3.1.0, < 3.1.15spring_data_keyvalue >= 3.2.0, < 3.2.16spring_data_keyvalue >= 3.3.0, < 3.3.17spring_data_keyvalue >= 3.4.0, < 3.4.15spring_data_keyvalue >= 3.5.0, < 3.5.11.1spring_data_keyvalue >= 4.0.0, < 4.0.5.1spring_data_redis >= 2.7.0, < 2.7.20spring_data_redis >= 3.0.0, < 3.0.16spring_data_redis >= 3.1.0, < 3.1.15spring_data_redis >= 3.2.0, < 3.2.16spring_data_redis >= 3.3.0, < 3.3.17spring_data_redis >= 3.4.0, < 3.4.15spring_data_redis >= 3.5.0, < 3.5.11.1spring_data_redis >= 4.0.0, < 4.0.5.1Upgrade past the affected range:
spring_data_keyvalue 4.0.5.1spring_data_redis 4.0.5.1Connected by shared product, vendor, weakness, or advisory.
CVE-2026-40985Medium· 6.4Applications that configure the WebFlowELExpressionParser are vulnerable to the use of malicious Unified EL expressions. Affected versions: Spring Web Flow 4.0.0; 3.0.0 through 3.0.1; 2.5.0 through 2.5.1.
CVE-2026-40478Critical· 9.0Thymeleaf is a server-side Java template engine for web and standalone environments
CVE-2026-40477Critical· 9.0Thymeleaf is a server-side Java template engine for web and standalone environments
CVE-2026-47878Medium· 5.6DefaultExecutionContextSerializer, used by default in Spring Batch's JDBC job repository, passes Base64-decoded bytes directly to ObjectInputStream.readObject() without an ObjectInputFilter that restricts types to a trusted class allowli…
CVE-2026-59326Low· 3.3The Spring Boot language server logs the raw value of the https_proxy/HTTPS_PROXY/http_proxy/HTTP_PROXY environment variable at INFO level whenever it creates an outbound HTTP client and no explicit http.proxy workspace setting is config…
CVE-2017-8039Medium· 5.9An issue was discovered in Pivotal Spring Web Flow through 2.4.5