org.springframework.data:spring-data-rest-core
Maven7 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting org.springframework.data:spring-data-rest-corepage 1 of 1
- CVE-2017-8046CRITICALCVSS 9.8EG 9.8fixed in 2.6.9.RELEASE or 3.0.1.RELEASE, by version range2018-01-04
vulnerable: 3.0.0.RELEASE
Malicious PATCH requests submitted to servers using Spring Data REST versions prior to 2.6.9 (Ingalls SR9), versions prior to 3.0.1 (Kay SR1) and Spring Boot versions prior to 1.5.9, 2.0 M6 can use specially crafted JSON data to run arbitr…
- CVE-2021-22047MEDIUMCVSS 5.3EG 5.3fixed in 3.4.14 or 3.5.6, by version range2021-10-28
vulnerable: 3.5.0 ... 3.5.5 (6 versions)
In Spring Data REST versions 3.4.0 - 3.4.13, 3.5.0 - 3.5.5, and older unsupported versions, HTTP resources implemented by custom controllers using a configured base API path and a controller type-level request mapping are additionally expo…
- CVE-2022-31679LOWCVSS 3.7EG 3.7fixed in 3.6.7 or 3.7.3, by version range2022-09-21
vulnerable: 3.7.0, 3.7.1, 3.7.2
Applications that allow HTTP PATCH access to resources exposed by Spring Data REST in versions 3.6.0 - 3.5.5, 3.7.0 - 3.7.2, and older unsupported versions, if an attacker knows about the structure of the underlying domain model, they can …
- CVE-2026-41728HIGHCVSS 7.5EG 7.5fixed in 5.0.6 or 4.5.12, by version range2026-06-10
vulnerable: 1.0.0.RELEASE ... 3.7.9 (180 versions)
Spring Data REST's JSON Patch (application/json-patch+json) implementation does not apply the write-access filter to intermediate path segments when resolving a multi-segment JSON Pointer. Affected versions: Spring Data REST 3.7.0 through…
- CVE-2026-41729HIGHCVSS 8.1EG 8.1fixed in 5.0.6 or 4.5.12, by version range2026-06-10
vulnerable: 1.0.0.RELEASE ... 3.7.9 (180 versions)
Spring Data REST is vulnerable to SpEL expression injection through map-typed properties when processing JSON Patch (application/json-patch+json) requests. When a persistent entity exposes a Map-typed property, the JSON Pointer path segmen…
- CVE-2026-41730MEDIUMCVSS 5.3EG 5.3fixed in 5.0.6 or 4.5.12, by version range2026-06-10
vulnerable: 1.0.0.RELEASE ... 3.7.9 (180 versions)
Spring Data REST serializes the full exception cause chain into HTTP error response bodies, potentially exposing persistence-layer internals to HTTP clients. Affected versions: Spring Data REST 3.7.0 through 3.7.19; 4.3.0 through 4.3.16; …
- CVE-2026-41837MEDIUMCVSS 5.3EG 5.3fixed in 5.0.6 or 4.5.12, by version range2026-06-10
vulnerable: 1.0.0.RELEASE ... 3.7.9 (180 versions)
Spring Data REST's Querydsl integration accepts arbitrary persistent property paths as request-parameter filter keys and does not consider Jackson customizations before handing them to Querydsl. Affected versions: Spring Data REST 3.7.0 t…
Check whether org.springframework.data:spring-data-rest-core is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for org.springframework.data:spring-data-rest-core CVEs against the assets you own.
Book a Demo →