org.springframework.data:spring-data-mongodb
Maven3 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting org.springframework.data:spring-data-mongodbpage 1 of 1
- CVE-2022-22980CRITICALCVSS 9.8EG 9.8✓ Fixed in 3.3.52022-06-23
vulnerable: 1.0.0.RELEASE ... 3.3.4 (173 versions)
A Spring Data MongoDB application is vulnerable to SpEL Injection when using @Query or @Aggregation-annotated query methods with SpEL expressions that contain query parameter placeholders for value binding if the input is not sanitized.
- CVE-2026-41696MEDIUMCVSS 5.9EG 5.9✓ Fixed in 5.0.62026-06-10
vulnerable: 5.0.0 ... 5.0.5 (6 versions)
Spring Data MongoDB repository query methods annotated with @Query that use regex parameter binding perform insufficient validation of the bound parameter. An attacker can supply a crafted string to break out of the intended regular expres…
- CVE-2026-41717HIGHCVSS 8.1EG 8.1✓ Fixed in 5.0.62026-06-10
vulnerable: 5.0.0 ... 5.0.5 (6 versions)
Spring Data MongoDB contains a SpEL (Spring Expression Language) expression injection vulnerability. The issue occurs during parameter binding when a user-defined repository query method is annotated with @Query and utilizes a capture-all …
Check whether org.springframework.data:spring-data-mongodb is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for org.springframework.data:spring-data-mongodb CVEs against the assets you own.
Start Free Scan →