Skip to content

CVE-2026-41728 (High) detected in spring-data-rest-webmvc-4.5.1.jar #376

Description

@mend-bolt-for-github

CVE-2026-41728 - High Severity Vulnerability

Vulnerable Library - spring-data-rest-webmvc-4.5.1.jar

Spring Data REST - WebMVC

Library home page: https://www.spring.io/spring-data

Path to dependency file: /pom.xml

Path to vulnerable library: /home/wss-scanner/.m2/repository/org/springframework/data/spring-data-rest-webmvc/4.5.1/spring-data-rest-webmvc-4.5.1.jar

Dependency Hierarchy:

  • spring-boot-starter-data-rest-3.5.3.jar (Root Library)
    • spring-data-rest-webmvc-4.5.1.jar (Vulnerable Library)

Found in HEAD commit: ddbf982f54a01dcec86cab13425f8047dcb250f3

Found in base branch: master

Vulnerability Details

Spring Data REST's JSON Patch (application/json-patch+json) implementation does not apply the write-access filter to intermediate path segments when resolving a multi-segment JSON Pointer.
Affected versions:
Spring Data REST 3.7.0 through 3.7.19; 4.3.0 through 4.3.16; 4.4.0 through 4.4.14; 4.5.0 through 4.5.11; 5.0.0 through 5.0.5.

Publish Date: 2026-06-09

URL: CVE-2026-41728

CVSS 3 Score Details (7.5)

Base Score Metrics:

  • Exploitability Metrics:
    • Attack Vector: Network
    • Attack Complexity: Low
    • Privileges Required: None
    • User Interaction: None
    • Scope: Unchanged
  • Impact Metrics:
    • Confidentiality Impact: None
    • Integrity Impact: High
    • Availability Impact: None

For more information on CVSS3 Scores, click here.

Suggested Fix

Type: Upgrade version

Origin: https://spring.io/security/cve-2026-41728

Release Date: 2026-06-09

Fix Resolution (org.springframework.data:spring-data-rest-webmvc): 4.5.12

Direct dependency fix Resolution (org.springframework.boot:spring-boot-starter-data-rest): 3.5.5


Step up your Open Source Security Game with Mend here

Metadata

Metadata

Assignees

No one assigned

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions