{
  "@id": "urn:uuid:e026858b-8d1b-41ff-b675-48250db4adfd",
  "role": "Document Creator",
  "author": "https://tuxcare.com",
  "version": 1,
  "@context": "https://openvex.dev/ns/v0.2.0",
  "timestamp": "2026-09-24T09:31:26.931840+00:00",
  "statements": [
    {
      "status": "not_affected",
      "products": [
        {
          "@id": "pkg:maven/org.springframework.data/spring-data-redis@2.6.10-tuxcare.1",
          "identifiers": {
            "purl": "pkg:maven/org.springframework.data/spring-data-redis@2.6.10-tuxcare.1"
          }
        }
      ],
      "timestamp": "2026-09-24T09:31:26.931840+00:00",
      "status_notes": "Vulnerability CVE-2026-41719 does not affect version 2.6.10-tuxcare.1 of org.springframework.data:spring-data-redis. not_affected \u2014 Spring-data-redis 2.6.10 is a library that depends on spring-data-keyvalue, which contains the vulnerable SpelPropertyComparator. While spring-data-redis uses this component through SpelSortAccessor in RedisQueryEngine (line 58), the library itself does not expose repository methods to untrusted input. The vulnerable code path exists but requires downstream applications to: (1) expose repositor...",
      "vulnerability": {
        "name": "CVE-2026-41719"
      },
      "impact_statement": "not_affected \u2014 Spring-data-redis 2.6.10 is a library that depends on spring-data-keyvalue, which contains the vulnerable SpelPropertyComparator. While spring-data-redis uses this component through SpelSortAccessor in RedisQueryEngine (line 58), the library itself does not expose repository methods to untrusted input. The vulnerable code path exists but requires downstream applications to: (1) expose repositor..."
    }
  ]
}
