PT-2026-108109 · Jhipster · Jhipster
CVE-2026-107375
·
Published
2026-10-08
·
Updated
2026-10-08
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
JHipster versions 7.0.0 through 9.3.x
Description
Reactive applications generated with Spring WebFlux, Spring Data R2DBC, and a SQL database are susceptible to SQL injection. The issue occurs because the
sort request parameter in paginated entity-list endpoints (e.g., /api/<entity>) is passed directly into the createOrderByFields() function without validation or quoting. This allows the user-supplied input to be rendered verbatim into the SQL ORDER BY clause. Since the R2DBC simple query protocol supports semicolon-separated statements, an authenticated user can execute arbitrary SQL commands. This can lead to unauthorized reading of sensitive tables (such as password hashes in jhi user), modification or deletion of data, and the dropping of database tables. Non-reactive JPA applications and NoSQL backends are not affected.Recommendations
Update JHipster to version 9.4.0 and regenerate the affected applications.
As a temporary mitigation, restrict access to the
sort parameter in paginated entity-list endpoints or implement strict server-side validation to allow only known column names.Fix
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Jhipster