← Back

CVE-2026-41696

nvd nist
Published: Jun 10, 2026Modified: Jul 17, 2026

JSON object

Loading...
5.9
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Exploitability: 2.2 / Impact: 3.6
Source: security@vmware.com (Secondary)

Description

Spring Data MongoDB repository query methods annotated with @Query that use regex parameter binding perform insufficient validation of the bound parameter. An attacker can supply a crafted string to break out of the intended regular expression quoting. Affected versions: Spring Data MongoDB 5.0.0 through 5.0.5; 4.5.0 through 4.5.11; 4.4.0 through 4.4.14; 4.3.0 through 4.3.16; 4.2.0 through 4.2.15; 4.1.0 through 4.1.14; 4.0.0 through 4.0.15; 3.4.0 through 3.4.19.

Affected (8)

1 product
Spring Data Mongodb
Configuration A
8 vulnerable
Vulnerable SoftwareAffected Versions
Vmware
From 3.4.0 to 3.4.20
From 4.0.0 to 4.0.15
From 4.1.0 to 4.1.14
From 4.2.0 to 4.2.15
From 4.3.0 to 4.3.17
From 4.4.0 to 4.4.15
From 4.5.0 to 4.5.11.1
From 5.0.0 to 5.0.5.1

References (1)

Source: security@vmware.com
Vendor Advisory

Timeline

No history available yet.