Intel

AIKIDO-2026-11183

spring-data-commons is vulnerable to Uncontrolled Resource Consumption

Uncontrolled Resource ConsumptionCVE-2026-41721 Published Jun 12, 2026

59

Medium Risk

This Affects:

JAVAspring-data-commons
0.0.1 - 3.5.11
Fixed in 3.5.12
4.0.0 - 4.0.5
Fixed in 4.0.6
Are you affected? Scan for Free

TL;DR

Spring Data Commons contains a vulnerability that can lead to a Denial of Service (DoS) condition if Spring Data Web Support is enabled in conjunction with a Controller method using @ProjectedPayload, when an attacker sends a specially crafted HTTP request that causes the application to allocate lots of memory.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

spring-data-commons is vulnerable to Uncontrolled Resource Consumption in versions 0.0.1 - 3.5.11 and 4.0.0 - 4.0.5.

How to fix this

Upgrade the org.springframework.data:spring-data-commons library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform