PT-2026-108109 · Jhipster · Jhipster

CVE-2026-107375

·

Published

2026-10-08

·

Updated

2026-10-08

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions JHipster versions 7.0.0 through 9.3.x
Description Reactive applications generated with Spring WebFlux, Spring Data R2DBC, and a SQL database are susceptible to SQL injection. The issue occurs because the sort request parameter in paginated entity-list endpoints (e.g., /api/<entity>) is passed directly into the createOrderByFields() function without validation or quoting. This allows the user-supplied input to be rendered verbatim into the SQL ORDER BY clause. Since the R2DBC simple query protocol supports semicolon-separated statements, an authenticated user can execute arbitrary SQL commands. This can lead to unauthorized reading of sensitive tables (such as password hashes in jhi user), modification or deletion of data, and the dropping of database tables. Non-reactive JPA applications and NoSQL backends are not affected.
Recommendations Update JHipster to version 9.4.0 and regenerate the affected applications. As a temporary mitigation, restrict access to the sort parameter in paginated entity-list endpoints or implement strict server-side validation to allow only known column names.

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-107375
GHSA-R223-96JV-Q533

Affected Products

Jhipster