Spring Data KeyValue/Redis SpEL Injection via Sort (4.0.5)
CVE-2026-41719 Published on June 9, 2026
Spring Data KeyValue - SpEL Injection vulnerability in SpelPropertyComparator
A SpEL Injection vulnerability exists in the Spring Data KeyValue if unsanitized user input is passed as Sort into a repository query method that delegates evaluation to the SpelPropertyComparator.
Affected versions:
Spring Data KeyValue / Spring Data Redis 4.0.0 through 4.0.5; 3.5.0 through 3.5.11; 3.4.0 through 3.4.14; 3.3.0 through 3.3.16; 3.2.0 through 3.2.15; 3.1.0 through 3.1.14; 3.0.0 through 3.0.15; 2.7.0 through 2.7.19.
Vulnerability Analysis
CVE-2026-41719 can be exploited with network access, and requires small amount of user privileges. This vulnerability is consided to have a high level of attack complexity. The potential impact of an exploit of this vulnerability is considered to have a high impact on confidentiality, with no impact on integrity and availability.
Weakness Type
What is an EL Injection Vulnerability?
The software constructs all or part of an expression language (EL) statement in a Java Server Page (JSP) using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended EL statement before it is executed.
CVE-2026-41719 has been classified to as an EL Injection vulnerability or weakness.
Products Associated with CVE-2026-41719
Want to know whenever a new CVE is published for VMware Spring Framework? stack.watch will email you.
Affected Versions
Spring Data KeyValue:- Version 4.0.0 and below 4.0.6 is affected.
- Version 3.5.0 and below 3.5.12 is affected.
- Version 3.4.0 and below 3.4.15 is affected.
- Version 3.3.0 and below 3.3.17 is affected.
- Version 3.2.0 and below 3.2.16 is affected.
- Version 3.1.0 and below 3.1.15 is affected.
- Version 3.0.0 and below 3.0.16 is affected.
- Version 2.7.0 and below 2.7.20 is affected.
- Version 4.0.0 and below 4.0.6 is affected.
- Version 3.5.0 and below 3.5.12 is affected.
- Version 3.4.0 and below 3.4.15 is affected.
- Version 3.3.0 and below 3.3.17 is affected.
- Version 3.2.0 and below 3.2.16 is affected.
- Version 3.1.0 and below 3.1.15 is affected.
- Version 3.0.0 and below 3.0.16 is affected.
- Version 2.7.0 and below 2.7.20 is affected.