CVE Wiki Pixee · CVE intelligence
← All CVEs

CVE-2017-8046

Critical · CVSS 9.8

spring-data-rest-core — JSON deserialization RCE via malicious PATCH request

CVSS
9.8
nvd
EPSS
KEV
No
Class
oss containerizable
CWE-20

Description

Malicious PATCH requests submitted to servers using Spring Data REST versions prior to 2.6.9 (Ingalls SR9), versions prior to 3.0.1 (Kay SR1) and Spring Boot versions prior to 1.5.9, 2.0 M6 can use specially crafted JSON data to run arbitrary Java code.

Search profile — drives PoC discovery

Symbols spring-data-rest-corePatchOperationSpelExpressionJsonPatchPatchConverterDomainObjectReaderorg.springframework.data.restPATCHSpEL injection
Keywords CVE-2017-8046Spring Data RESTPATCH RCESpring Boot deserializationSpEL injectionspring-data-rest exploitIngalls SR9Kay SR1arbitrary code execution PATCHspring-data-rest-core PoC
Versions: spring-data-rest-core < 2.6.9 (Ingalls SR9), < 3.0.1 (Kay SR1); Spring Boot < 1.5.9, < 2.0 M6

Ranked PoCs (43) — best first

Heuristic ranking — not yet expert-vetted. Scored on structure + provenance, not execution.

Recall-favoring discovery; ranking by the Stage-4 scorer (Adam's rubric). Scanner/aggregator repos are hidden.

Affected packages

Maven org.springframework.data:spring-data-rest-core 0 → 2.6.9.RELEASE
Maven org.springframework.data:spring-data-rest-core 3.0.0 → 3.0.1.RELEASE

References

Status: enriched · ingested 2026-06-27T00:00:38.000Z · profiled 2026-06-30T18:10:12.581Z