High severity7.5NVD Advisory· Published Jun 10, 2026· Updated Jun 16, 2026
CVE-2026-41695
CVE-2026-41695
Description
Spring Data Commons applications may be vulnerable to denial of service through resource exhaustion when attacker-controlled property path strings are passed to MappingContext property path resolution.
Affected versions: Spring Data Commons 4.0.0 through 4.0.5; 3.5.0 through 3.5.11; 3.4.0 through 3.4.14.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2- cpe:2.3:a:broadcom:spring_data_commons:*:*:*:*:*:*:*:*Range: >=3.4.0,<3.4.15
- Range: 4.0.0-4.0.5, 3.5.0-3.5.11, 3.4.0-3.4.14
Patches
Vulnerability mechanics
References
1- spring.io/security/cve-2026-41695nvdVendor Advisory
News mentions
1- Spring Projects: 25 Vulnerabilities Disclosed, Including SpEL Injection and Deserialization FlawsVypr Intelligence · Jun 10, 2026