Sort Validation Bypass in Spring Data JPA by Vendor Spring
CVE-2026-47834
4.8MEDIUM
What is CVE-2026-47834?
The vulnerability in Spring Data JPA allows an attacker to bypass sort validation by passing crafted payloads through untrusted sources. This can lead to potential unauthorized access to advanced sorting functionality, exposing sensitive data or enabling additional attacks. It is crucial for users of the affected Spring Data JPA versions to review their implementations and apply security patches as recommended.
Affected Version(s)
Spring Data JPA 4.1.0
Spring Data JPA 4.0.0 <= 4.0.6
Spring Data JPA 3.5.0 <= 3.5.13
