Junglewise Threat Intelligence

CVE-2026-41697: VMware Spring Data Relational improper input escaping in Query By Example

CVE-2026-41697 · Severity: medium · CVSS 4.8 · Published 2026-06-10

Vendors: VMware.

Executive brief

Spring Data Relational is a software library used by Java applications to interact with databases. A security flaw in how it handles search queries allows an attacker to use special characters to guess sensitive information stored in the database. This could lead to unauthorized data discovery or minor service disruptions.

Technical details

A vulnerability exists in Spring Data Relational (including JDBC and R2DBC modules) due to improper neutralization of special elements in data query logic (CWE-943). When using the 'Query By Example' (QBE) feature with StringMatcher options such as STARTING, ENDING, or CONTAINING, the library fails to properly escape wildcard characters in user-provided input. A remote attacker can exploit this by supplying malicious wildcard characters to perform boolean-based blind data inference, effectively leaking data through a series of true/false queries. Patches are available in versions 4.0.6 and 3.5.12.

Affected products

  • VMware Spring Data Relational 4.0.0 to 4.0.5, 3.5.0 to 3.5.11, 3.4.0 to 3.4.14, 3.3.0 to 3.3.16, 3.2.0 to 3.2.15, 3.1.0 to 3.1.14, 3.0.0 to 3.0.15, 2.4.0 to 2.4.19

Timeline

  • 2026-06-10: disclosed
  • 2026-06-10: advisory

References