Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-41716

Опубликовано: 09 июн. 2026
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

Spring Data's internal property-lookup cache accepts and permanently retains attacker-supplied strings as cache keys, allowing heap exhaustion through repeated requests. Affected versions: Spring Data Commons 2.7.0 through 2.7.19; 3.3.0 through 3.3.16; 3.4.0 through 3.4.14; 3.5.0 through 3.5.11; 4.0.0 through 4.0.5.

A flaw was found in Spring Data Commons. An attacker can exploit this vulnerability by sending repeated requests with specially crafted strings, which are then permanently retained in the internal property-lookup cache. This can lead to heap exhaustion, resulting in a Denial of Service (DoS) for the affected system.

Отчет

A flaw was found in Spring Data Commons. The TypeDiscoverer cache can be exhausted by sending many unique invalid property names, leading to denial of service through excessive memory consumption. Red Hat products that bundle spring-data-commons and expose Spring Data query resolution to untrusted input are affected. In Red Hat Dev Spaces, the vulnerable code path is reachable only through admin-authenticated endpoints, limiting practical exploitability.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Data Grid 8spring-data-commonsNot affected
Red Hat Fuse 7spring-data-commonsWill not fix
Red Hat JBoss Enterprise Application Platform Expansion Packspring-data-commonsNot affected
Red Hat OpenShift Dev Spacesdevspaces/openvsx-rhel9Affected
Red Hat OpenShift Dev Spacesdevspaces/pluginregistry-rhel9Affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-770
https://bugzilla.redhat.com/show_bug.cgi?id=2487394Spring Data Commons: Spring Data Commons: Denial of Service due to cache exhaustion via attacker-supplied strings

EPSS

Процентиль: 29%
0.00363
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
nvd
2 месяца назад

Spring Data's internal property-lookup cache accepts and permanently retains attacker-supplied strings as cache keys, allowing heap exhaustion through repeated requests. Affected versions: Spring Data Commons 2.7.0 through 2.7.19; 3.3.0 through 3.3.16; 3.4.0 through 3.4.14; 3.5.0 through 3.5.11; 4.0.0 through 4.0.5.

CVSS3: 7.5
github
2 месяца назад

Spring Data's internal property-lookup cache accepts and permanently retains attacker-supplied strings as cache keys, allowing heap exhaustion through repeated requests. Affected versions: Spring Data Commons 2.7.0 through 2.7.19; 3.3.0 through 3.3.16; 3.4.0 through 3.4.14; 3.5.0 through 3.5.11; 4.0.0 through 4.0.5.

EPSS

Процентиль: 29%
0.00363
Низкий

7.5 High

CVSS3