← العودة للجدول
CVE-2026-41729
CVE-2026-41729 — Spring Data REST is vulnerable to SpEL expression injection through map-typed pr
📅 2026-06-10
🟠 High 🔥 No NVD Exploit Vulnerability CVSS 8.1

📋 الوصف الكامل

Spring Data REST is vulnerable to SpEL expression injection through map-typed properties when processing JSON Patch (application/json-patch+json) requests. When a persistent entity exposes a Map-typed property, the JSON Pointer path segment used as the map key is embedded directly into a SpEL expression without sanitization or validation. Affected versions: Spring Data REST 3.7.0 through 3.7.19;

💻 الأنظمة المتأثرة

Spring Framework

⚠️ نوع التهديد

Exploit

🔗 CVE ID

CVE-2026-41729

📡 المصدر

NVD

✅ الحلول والتخفيف

Update to v3.7.0

🔗 المصدر الأصلي ← 📘 NVD ← ⚡ CISA KEV ←