Vulnerable Library - spring-boot-starter-data-rest-3.1.12.jar
Sample Path to Dependency File: /pom.xml
Path to vulnerable library: /home/wss-scanner/.m2/repository/org/springframework/data/spring-data-rest-core/4.1.12/spring-data-rest-core-4.1.12.jar
Found in HEAD commit: 985d4a71b0cc06b07e4e37fda7739bbfc0dfc733
Vulnerabilities
| Vulnerability |
Severity |
CVSS |
Dependency |
Type |
Fixed in (spring-boot-starter-data-rest version) |
Remediation Possible** |
| CVE-2026-47849 |
High |
7.1 |
spring-data-rest-core-4.1.12.jar |
Transitive |
N/A* |
❌ |
| CVE-2026-47850 |
Medium |
4.3 |
spring-data-rest-webmvc-4.1.12.jar |
Transitive |
N/A* |
❌ |
*For some transitive vulnerabilities, there is no version of direct dependency with a fix. Check the "Details" section below to see if there is a version of transitive dependency where vulnerability is fixed.
**In some cases, Remediation PR cannot be created automatically for a vulnerability despite the availability of remediation
Details
CVE-2026-47849
Vulnerable Library - spring-data-rest-core-4.1.12.jar
Spring Data REST - Core
Library home page: https://www.spring.io
Sample Path to Dependency File: /pom.xml
Path to vulnerable library: /home/wss-scanner/.m2/repository/org/springframework/data/spring-data-rest-core/4.1.12/spring-data-rest-core-4.1.12.jar
Dependency Hierarchy:
- spring-boot-starter-data-rest-3.1.12.jar (Root Library)
- spring-data-rest-webmvc-4.1.12.jar
- ❌ spring-data-rest-core-4.1.12.jar (Vulnerable Library)
Found in HEAD commit: 985d4a71b0cc06b07e4e37fda7739bbfc0dfc733
Found in base branch: master
Vulnerability Details
Spring Data REST does not guard identifier (@Id) and version (@Version) properties against mutation via RFC 6902 JSON Patch (application/json-patch+json) requests.
Spring Data REST 5.1.0
Spring Data REST 5.0.0 - 5.0.6
Spring Data REST 4.5.0 - 4.5.12
Spring Data REST 4.0.0 - 4.4.15
Spring Data REST 3.7.20 and earlier
Publish Date: 2026-08-27
URL: CVE-2026-47849
CVSS 3 Score Details (7.1)
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: Low
- User Interaction: None
- Scope: Unchanged
- Impact Metrics:
- Confidentiality Impact: Low
- Integrity Impact: High
- Availability Impact: None
For more information on CVSS3 Scores, click here.
Suggested Fix
Type: Upgrade version
Origin: https://spring.io/security/cve-2026-47849
Release Date: 2026-08-27
Fix Resolution: org.springframework.data:spring-data-rest-core:5.0.7,org.springframework.data:spring-data-rest-core:5.1.1,org.springframework.data:spring-data-rest-core:4.5.13
Step up your Open Source Security Game with Mend here
CVE-2026-47850
Vulnerable Library - spring-data-rest-webmvc-4.1.12.jar
Spring Data REST - WebMVC
Library home page: https://www.spring.io
Sample Path to Dependency File: /pom.xml
Path to vulnerable library: /home/wss-scanner/.m2/repository/org/springframework/data/spring-data-rest-webmvc/4.1.12/spring-data-rest-webmvc-4.1.12.jar
Dependency Hierarchy:
- spring-boot-starter-data-rest-3.1.12.jar (Root Library)
- ❌ spring-data-rest-webmvc-4.1.12.jar (Vulnerable Library)
Found in HEAD commit: 985d4a71b0cc06b07e4e37fda7739bbfc0dfc733
Found in base branch: master
Vulnerability Details
Spring Data REST does not preserve the persisted version (@Version) property of an aggregate root when handling an HTTP PUT against an immutable target type.
Spring Data REST 5.1.0
Spring Data REST 5.0.0 - 5.0.6
Spring Data REST 4.5.0 - 4.5.12
Spring Data REST 4.0.0 - 4.4.15
Spring Data REST 3.7.20 and earlier
Publish Date: 2026-08-26
URL: CVE-2026-47850
CVSS 3 Score Details (4.3)
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: Low
- User Interaction: None
- Scope: Unchanged
- Impact Metrics:
- Confidentiality Impact: None
- Integrity Impact: Low
- Availability Impact: None
For more information on CVSS3 Scores, click here.
Suggested Fix
Type: Upgrade version
Release Date: 2026-08-26
Fix Resolution: org.springframework.data:spring-data-rest-webmvc:5.1.1,org.springframework.data:spring-data-rest-webmvc:5.0.7,https://github.com/spring-projects/spring-data-rest.git - 5.1.1,https://github.com/spring-projects/spring-data-rest.git - 4.5.13,org.springframework.data:spring-data-rest-webmvc:4.5.13,https://github.com/spring-projects/spring-data-rest.git - 5.0.7
Step up your Open Source Security Game with Mend here
Sample Path to Dependency File: /pom.xml
Path to vulnerable library: /home/wss-scanner/.m2/repository/org/springframework/data/spring-data-rest-core/4.1.12/spring-data-rest-core-4.1.12.jar
Found in HEAD commit: 985d4a71b0cc06b07e4e37fda7739bbfc0dfc733
Vulnerabilities
*For some transitive vulnerabilities, there is no version of direct dependency with a fix. Check the "Details" section below to see if there is a version of transitive dependency where vulnerability is fixed.
**In some cases, Remediation PR cannot be created automatically for a vulnerability despite the availability of remediation
Details
Vulnerable Library - spring-data-rest-core-4.1.12.jar
Spring Data REST - Core
Library home page: https://www.spring.io
Sample Path to Dependency File: /pom.xml
Path to vulnerable library: /home/wss-scanner/.m2/repository/org/springframework/data/spring-data-rest-core/4.1.12/spring-data-rest-core-4.1.12.jar
Dependency Hierarchy:
Found in HEAD commit: 985d4a71b0cc06b07e4e37fda7739bbfc0dfc733
Found in base branch: master
Vulnerability Details
Spring Data REST does not guard identifier (@Id) and version (@Version) properties against mutation via RFC 6902 JSON Patch (application/json-patch+json) requests.
Spring Data REST 5.1.0
Spring Data REST 5.0.0 - 5.0.6
Spring Data REST 4.5.0 - 4.5.12
Spring Data REST 4.0.0 - 4.4.15
Spring Data REST 3.7.20 and earlier
Publish Date: 2026-08-27
URL: CVE-2026-47849
CVSS 3 Score Details (7.1)
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: Low
- User Interaction: None
- Scope: Unchanged
- Impact Metrics:
- Confidentiality Impact: Low
- Integrity Impact: High
- Availability Impact: None
For more information on CVSS3 Scores, click here.Suggested Fix
Type: Upgrade version
Origin: https://spring.io/security/cve-2026-47849
Release Date: 2026-08-27
Fix Resolution: org.springframework.data:spring-data-rest-core:5.0.7,org.springframework.data:spring-data-rest-core:5.1.1,org.springframework.data:spring-data-rest-core:4.5.13
Step up your Open Source Security Game with Mend here
Vulnerable Library - spring-data-rest-webmvc-4.1.12.jar
Spring Data REST - WebMVC
Library home page: https://www.spring.io
Sample Path to Dependency File: /pom.xml
Path to vulnerable library: /home/wss-scanner/.m2/repository/org/springframework/data/spring-data-rest-webmvc/4.1.12/spring-data-rest-webmvc-4.1.12.jar
Dependency Hierarchy:
Found in HEAD commit: 985d4a71b0cc06b07e4e37fda7739bbfc0dfc733
Found in base branch: master
Vulnerability Details
Spring Data REST does not preserve the persisted version (@Version) property of an aggregate root when handling an HTTP PUT against an immutable target type.
Spring Data REST 5.1.0
Spring Data REST 5.0.0 - 5.0.6
Spring Data REST 4.5.0 - 4.5.12
Spring Data REST 4.0.0 - 4.4.15
Spring Data REST 3.7.20 and earlier
Publish Date: 2026-08-26
URL: CVE-2026-47850
CVSS 3 Score Details (4.3)
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: Low
- User Interaction: None
- Scope: Unchanged
- Impact Metrics:
- Confidentiality Impact: None
- Integrity Impact: Low
- Availability Impact: None
For more information on CVSS3 Scores, click here.Suggested Fix
Type: Upgrade version
Release Date: 2026-08-26
Fix Resolution: org.springframework.data:spring-data-rest-webmvc:5.1.1,org.springframework.data:spring-data-rest-webmvc:5.0.7,https://github.com/spring-projects/spring-data-rest.git - 5.1.1,https://github.com/spring-projects/spring-data-rest.git - 4.5.13,org.springframework.data:spring-data-rest-webmvc:4.5.13,https://github.com/spring-projects/spring-data-rest.git - 5.0.7
Step up your Open Source Security Game with Mend here