Intel

AIKIDO-2026-11186

spring-data-commons is vulnerable to Uncontrolled Resource Consumption

Uncontrolled Resource ConsumptionCVE-2026-41695 Published Jun 12, 2026

75

High Risk

This Affects:

JAVAspring-data-commons
3.4.0 - 3.5.11
Fixed in 3.5.12
4.0.0 - 4.0.5
Fixed in 4.0.6
Are you affected? Scan for Free

TL;DR

Spring Data Commons applications may be vulnerable to denial of service through resource exhaustion when attacker-controlled property path strings are passed to MappingContext property path resolution.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range and requires attacker-controlled property path input, exposure to untrusted callers, and recursive/deeply nested domain graphs or many unique invalid paths.

Background info

spring-data-commons is vulnerable to Uncontrolled Resource Consumption in versions 3.4.0 - 3.5.11 and 4.0.0 - 4.0.5.

How to fix this

Upgrade the org.springframework.data:spring-data-commons library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform