Intel

AIKIDO-2026-11179

spring-data-mongodb is vulnerable to SpEL Expression Injection

SpEL Expression InjectionCVE-2026-41717 Published Jun 12, 2026

81

High Risk

This Affects:

JAVAspring-data-mongodb
0.0.0 - 4.5.11
Fixed in 4.5.12
5.0.0 - 5.0.5
Fixed in 5.0.6
Are you affected? Scan for Free

TL;DR

Spring Data MongoDB contains a SpEL (Spring Expression Language) expression injection vulnerability. The issue occurs during parameter binding when a user-defined repository query method is annotated with @Query and utilizes a capture-all placeholder.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

spring-data-mongodb is vulnerable to SpEL Expression Injection in versions 0.0.0 - 4.5.11 and 5.0.0 - 5.0.5.

How to fix this

Upgrade the org.springframework.data:spring-data-mongodb library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform