Information Exposure in Spring Data REST by Pivotal
CVE-2026-41730

5.3MEDIUM

Key Information:

Vendor

Spring

Vendor
CVE Published:
9 June 2026

What is CVE-2026-41730?

The Spring Data REST framework contains a vulnerability that allows for the serialization of the full exception cause chain into HTTP error responses. This could result in the exposure of sensitive data related to the persistence layer to clients that receive these responses. Such exposure could lead to further exploitation if attackers leverage insights from the error details to compromise the integrity or confidentiality of the system.

Affected Version(s)

Spring Data REST 3.7.0 < 3.7.20

Spring Data REST 4.3.0 < 4.3.17

Spring Data REST 4.4.0 < 4.4.15

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.