VYPR

Maven package

org.springframework.data/spring-data-commons

pkg:maven/org.springframework.data/spring-data-commons

Vulnerabilities (5)

  • CVE-2026-41716HigJun 10, 2026
    affected >= 4.0.0, < 4.0.6fixed 4.0.6

    Spring Data's internal property-lookup cache accepts and permanently retains attacker-supplied strings as cache keys, allowing heap exhaustion through repeated requests. Affected versions: Spring Data Commons 2.7.0 through 2.7.19; 3.3.0 through 3.3.16; 3.4.0 through 3.4.14; 3.5.

  • CVE-2026-41711MedJun 10, 2026
    affected >= 4.0.0, < 4.0.6fixed 4.0.6

    Applications using Spring Data Commons may be vulnerable to a Denial of Service (DoS) attack leading to a StackOverflowException when parsing Sort parameters. Affected versions: Spring Data Commons 4.0.0 through 4.0.5; 3.5.0 through 3.5.11; 3.4.0 through 3.4.14; 3.3.0 through 3.

  • CVE-2018-1259HigMay 11, 2018
    affected >= 1.13.0, < 1.13.12fixed 1.13.12

    Spring Data Commons, versions 1.13 prior to 1.13.12 and 2.0 prior to 2.0.7, used in combination with XMLBeam 1.4.14 or earlier versions, contains a property binder vulnerability caused by improper restriction of XML external entity references as underlying library XMLBeam does no

  • CVE-2018-1274HigApr 18, 2018
    affected < 1.13.11fixed 1.13.11

    Spring Data Commons, versions 1.13 to 1.13.10, 2.0 to 2.0.5, and older unsupported versions, contain a property path parser vulnerability caused by unlimited resource allocation. An unauthenticated remote malicious user (or attacker) can issue requests against Spring Data REST en

  • CVE-2018-1273CriKEVApr 11, 2018
    affected >= 1.13.0, < 1.13.11fixed 1.13.11

    Spring Data Commons, versions prior to 1.13 to 1.13.10, 2.0 to 2.0.5, and older unsupported versions, contain a property binder vulnerability caused by improper neutralization of special elements. An unauthenticated remote malicious user (or attacker) can supply specially crafted