Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-41711

Опубликовано: 09 июн. 2026
Источник: redhat
CVSS3: 5.9
EPSS Низкий

Описание

Applications using Spring Data Commons may be vulnerable to a Denial of Service (DoS) attack leading to a StackOverflowException when parsing Sort parameters. Affected versions: Spring Data Commons 4.0.0 through 4.0.5; 3.5.0 through 3.5.11; 3.4.0 through 3.4.14; 3.3.0 through 3.3.16; 3.2.0 through 3.2.15; 3.1.0 through 3.1.14; 3.0.0 through 3.0.15; 2.7.0 through 2.7.19.

A flaw was found in Spring Data Commons. Applications using this component may be vulnerable to a Denial of Service (DoS) attack. A remote attacker could exploit this by sending specially crafted Sort parameters, leading to a StackOverflowException and causing the application to become unavailable.

Отчет

A flaw was found in Spring Data Commons. Crafted Sort parameter strings can cause unbounded recursion in PropertyPath resolution, leading to a StackOverflowError and denial of service. Exploitation requires the application to expose endpoints accepting Sort parameters from untrusted sources without validation.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Data Grid 8spring-data-commonsFix deferred
Red Hat Fuse 7spring-data-commonsOut of support scope
Red Hat JBoss Enterprise Application Platform Expansion Packspring-data-commonsFix deferred
Red Hat OpenShift Dev Spacesdevspaces/openvsx-rhel9Fix deferred
Red Hat OpenShift Dev Spacesdevspaces/pluginregistry-rhel9Out of support scope

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-606
https://bugzilla.redhat.com/show_bug.cgi?id=2487403Spring Data Commons: Spring Data Commons: Denial of Service via parsing Sort parameters

EPSS

Процентиль: 20%
0.0028
Низкий

5.9 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.9
nvd
2 месяца назад

Applications using Spring Data Commons may be vulnerable to a Denial of Service (DoS) attack leading to a StackOverflowException when parsing Sort parameters. Affected versions: Spring Data Commons 4.0.0 through 4.0.5; 3.5.0 through 3.5.11; 3.4.0 through 3.4.14; 3.3.0 through 3.3.16; 3.2.0 through 3.2.15; 3.1.0 through 3.1.14; 3.0.0 through 3.0.15; 2.7.0 through 2.7.19.

CVSS3: 5.9
github
2 месяца назад

Applications using Spring Data Commons may be vulnerable to a Denial of Service (DoS) attack leading to a StackOverflowException when parsing Sort parameters. Affected versions: Spring Data Commons 4.0.0 through 4.0.5; 3.5.0 through 3.5.11; 3.4.0 through 3.4.14; 3.3.0 through 3.3.16; 3.2.0 through 3.2.15; 3.1.0 through 3.1.14; 3.0.0 through 3.0.15; 2.7.0 through 2.7.19.

EPSS

Процентиль: 20%
0.0028
Низкий

5.9 Medium

CVSS3