← Back

CVE-2026-41717

nvd nist
Published: Jun 10, 2026Modified: Jul 17, 2026

JSON object

Loading...
8.1
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 2.2 / Impact: 5.9
Source: security@vmware.com (Secondary)

Description

Spring Data MongoDB contains a SpEL (Spring Expression Language) expression injection vulnerability. The issue occurs during parameter binding when a user-defined repository query method is annotated with @Query and utilizes a capture-all placeholder. Affected versions: Spring Data MongoDB 5.0.0 through 5.0.5; 4.5.0 through 4.5.11; 4.4.0 through 4.4.14; 4.3.0 through 4.3.16; 4.2.0 through 4.2.15; 4.1.0 through 4.1.14; 4.0.0 through 4.0.15; 3.4.0 through 3.4.19.

Affected (8)

1 product
Spring Data Mongodb
Configuration A
8 vulnerable
Vulnerable SoftwareAffected Versions
Vmware
From 3.4.0 to 3.4.20
From 4.0.0 to 4.0.16
From 4.1.0 to 4.1.15
From 4.2.0 to 4.2.16
From 4.3.0 to 4.3.17
From 4.4.0 to 4.4.15
From 4.5.0 to 4.5.11.1
From 5.0.0 to 5.0.5.1

References (1)

Source: security@vmware.com
Vendor Advisory

Timeline

No history available yet.