Intel

AIKIDO-2026-11181

spring-data-redis is vulnerable to SpEL Injection

SpEL InjectionCVE-2026-41719 Published Jun 12, 2026

64

Medium Risk

This Affects:

JAVAspring-data-redis
0.0.1 - 3.5.11
Fixed in 3.5.12
4.0.0 - 4.0.5
Fixed in 4.0.6
Are you affected? Scan for Free

TL;DR

A SpEL Injection vulnerability exists in the Spring Data KeyValue if unsanitized user input is passed as Sort into a repository query method that delegates evaluation to the SpelPropertyComparator.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range and if SpelPropertyComparator is used with untrusted input for sorting.

Background info

spring-data-redis is vulnerable to SpEL Injection in versions 0.0.1 - 3.5.11 and 4.0.0 - 4.0.5.

How to fix this

Upgrade the org.springframework.data:spring-data-redis library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform