CVE-2026-41729 - Spring Data REST SpEL Injection via Map Key in JSON Patch
CVE ID :CVE-2026-41729 Published : June 10, 2026, 12:16 a.m. | 59 minutes ago Description :Spring Data REST is vulnerable to SpEL expression injection through map-typed properties when processing JSON Patch (application/json-patch+json) requests. When a persistent entity exposes a Map-typed...