High severity7.5NVD Advisory· Published Jun 10, 2026· Updated Jun 16, 2026
CVE-2026-41716
CVE-2026-41716
Description
Spring Data's internal property-lookup cache accepts and permanently retains attacker-supplied strings as cache keys, allowing heap exhaustion through repeated requests.
Affected versions: Spring Data Commons 2.7.0 through 2.7.19; 3.3.0 through 3.3.16; 3.4.0 through 3.4.14; 3.5.0 through 3.5.11; 4.0.0 through 4.0.5.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2- cpe:2.3:a:broadcom:spring_data_commons:*:*:*:*:*:*:*:*Range: >=2.7.0,<2.7.20
- Range: 2.7.0 - 2.7.19; 3.3.0 - 3.3.16; 3.4.0 - 3.4.14; 3.5.0 - 3.5.11; 4.0.0 - 4.0.5
Patches
Vulnerability mechanics
References
1- spring.io/security/cve-2026-41716nvdVendor Advisory
News mentions
1- Spring Projects: 25 Vulnerabilities Disclosed, Including SpEL Injection and Deserialization FlawsVypr Intelligence · Jun 10, 2026