Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-41695

Опубликовано: 09 июн. 2026
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

Spring Data Commons applications may be vulnerable to denial of service through resource exhaustion when attacker-controlled property path strings are passed to MappingContext property path resolution. Affected versions: Spring Data Commons 4.0.0 through 4.0.5; 3.5.0 through 3.5.11; 3.4.0 through 3.4.14.

A flaw was found in Spring Data Commons. A remote attacker can exploit this vulnerability by providing specially crafted property path strings to the MappingContext property path resolution. This can lead to resource exhaustion, resulting in a denial of service (DoS) for affected applications.

Отчет

A flaw was found in Spring Data Commons. Crafted property path strings can trigger excessive processing, leading to denial of service. Red Hat products that bundle spring-data-commons and expose Spring Data query resolution to untrusted input are affected. In Red Hat Dev Spaces, the vulnerable code path is reachable only through admin-authenticated endpoints, limiting practical exploitability.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Data Grid 8spring-data-commonsNot affected
Red Hat Fuse 7spring-data-commonsWill not fix
Red Hat JBoss Enterprise Application Platform Expansion Packspring-data-commonsNot affected
Red Hat OpenShift Dev Spacesdevspaces/openvsx-rhel9Out of support scope
Red Hat OpenShift Dev Spacesdevspaces/pluginregistry-rhel9Out of support scope

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-770
https://bugzilla.redhat.com/show_bug.cgi?id=2487386Spring Data Commons: Spring Data Commons: Denial of Service via crafted property path strings

EPSS

Процентиль: 29%
0.00363
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
nvd
2 месяца назад

Spring Data Commons applications may be vulnerable to denial of service through resource exhaustion when attacker-controlled property path strings are passed to MappingContext property path resolution. Affected versions: Spring Data Commons 4.0.0 through 4.0.5; 3.5.0 through 3.5.11; 3.4.0 through 3.4.14.

CVSS3: 7.5
github
10 дней назад

Spring Data: Unbounded property-path cache keyed by externally-supplied path string

EPSS

Процентиль: 29%
0.00363
Низкий

7.5 High

CVSS3