Sort Validation Bypass in Spring Data JPA by Vendor Spring
CVE-2026-47834

4.8MEDIUM

Key Information:

Vendor

Spring

Vendor
CVE Published:
26 August 2026

What is CVE-2026-47834?

The vulnerability in Spring Data JPA allows an attacker to bypass sort validation by passing crafted payloads through untrusted sources. This can lead to potential unauthorized access to advanced sorting functionality, exposing sensitive data or enabling additional attacks. It is crucial for users of the affected Spring Data JPA versions to review their implementations and apply security patches as recommended.

Affected Version(s)

Spring Data JPA 4.1.0

Spring Data JPA 4.0.0 <= 4.0.6

Spring Data JPA 3.5.0 <= 3.5.13

References

CVSS V3.1

Score:
4.8
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.