JSON Patch Vulnerability in Spring Data REST by Pivotal
CVE-2026-41728

7.5HIGH

Key Information:

Vendor

Spring

Vendor
CVE Published:
9 June 2026

What is CVE-2026-41728?

The vulnerability in Spring Data REST's JSON Patch implementation allows the write-access filter to be bypassed for intermediate path segments in multi-segment JSON Pointers. This compromise can lead to unintended data manipulation or exposure, highlighting a critical need for users to secure their deployments immediately. Developers and systems administrators should review affected versions ranging from 3.7.0 to 5.0.5 and implement patches provided by Pivotal to mitigate potential risks associated with this flaw.

Affected Version(s)

Spring Data REST 3.7.0 < 3.7.20

Spring Data REST 4.3.0 < 4.3.17

Spring Data REST 4.4.0 < 4.4.15

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.