Vmware · Spring Data Jpa · CVE-2026-47834
**Name of the Vulnerable Software and Affected Versions**
Spring Data JPA version 4.1.0
Spring Data JPA versions 4.0.0 through 4.0.6
Spring Data JPA versions 3.5.0 through 3.5.13
Spring Data JPA versions 3.0.0 through 3.4.15
**Description**
Sort validation can be bypassed when parameters containing crafted payloads are accepted from untrusted sources.
**Recommendations**
At the moment, there is no information about a newer version that contains a fix for this vulnerability.