org.springframework.data:spring-data-commons
Maven7 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting org.springframework.data:spring-data-commonspage 1 of 1
- CVE-2018-1259HIGHCVSS 7.5EG 7.5fixed in 1.13.12 or 2.0.7, by version range2018-05-11
vulnerable: 2.0.0.RELEASE ... 2.0.6.RELEASE (7 versions)
Spring Data Commons, versions 1.13 prior to 1.13.12 and 2.0 prior to 2.0.7, used in combination with XMLBeam 1.4.14 or earlier versions, contains a property binder vulnerability caused by improper restriction of XML external entity referen…
- CVE-2018-1273CRITICALCVSS 9.8EG 9.8⚠ KEVfixed in 1.13.11 or 2.0.6, by version range2018-04-11
vulnerable: 2.0.0.RELEASE ... 2.0.5.RELEASE (6 versions)
Spring Data Commons, versions prior to 1.13 to 1.13.10, 2.0 to 2.0.5, and older unsupported versions, contain a property binder vulnerability caused by improper neutralization of special elements. An unauthenticated remote malicious user (…
- CVE-2018-1274HIGHCVSS 7.5EG 7.5fixed in 1.13.11 or 2.0.6, by version range2018-04-18
vulnerable: 2.0.0.RELEASE ... 2.0.5.RELEASE (6 versions)
Spring Data Commons, versions 1.13 to 1.13.10, 2.0 to 2.0.5, and older unsupported versions, contain a property path parser vulnerability caused by unlimited resource allocation. An unauthenticated remote malicious user (or attacker) can i…
- CVE-2026-41695HIGHCVSS 7.5EG 7.5fixed in 4.0.6 or 3.5.12, by version range2026-06-10
vulnerable: 3.4.0 ... 3.4.9 (14 versions)
Spring Data Commons applications may be vulnerable to denial of service through resource exhaustion when attacker-controlled property path strings are passed to MappingContext property path resolution. Affected versions: Spring Data Commo…
- CVE-2026-41711MEDIUMCVSS 5.9EG 5.9fixed in 4.0.6 or 3.5.12, by version range2026-06-10
vulnerable: 1.10.0.RELEASE ... 2.7.9 (189 versions)
Applications using Spring Data Commons may be vulnerable to a Denial of Service (DoS) attack leading to a StackOverflowException when parsing Sort parameters. Affected versions: Spring Data Commons 4.0.0 through 4.0.5; 3.5.0 through 3.5.1…
- CVE-2026-41716HIGHCVSS 7.5EG 7.5fixed in 4.0.6 or 3.5.12, by version range2026-06-10
vulnerable: 1.10.0.RELEASE ... 2.7.9 (189 versions)
Spring Data's internal property-lookup cache accepts and permanently retains attacker-supplied strings as cache keys, allowing heap exhaustion through repeated requests. Affected versions: Spring Data Commons 2.7.0 through 2.7.19; 3.3.0 t…
- CVE-2026-41721MEDIUMCVSS 5.9EG 5.9fixed in 4.0.6 or 3.5.12, by version range2026-06-10
vulnerable: 1.10.0.RELEASE ... 2.7.9 (189 versions)
Spring Data Commons contains a vulnerability that can lead to a Denial of Service (DoS) condition if Spring Data Web Support is enabled in conjunction with a Controller method using @ProjectedPayload, when an attacker sends a specially cra…
Check whether org.springframework.data:spring-data-commons is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for org.springframework.data:spring-data-commons CVEs against the assets you own.
Book a Demo →