MongoDB support for Spring Data
92%
Total Score
99
47
100
100
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2026-11179 spring-data-mongodb is vulnerable to SpEL Expression Injection in versions 0.0.0 - 3.4.19, 4.0.0 - 4.3.16, 4.4.0 - 4.4.14, 4.5.0 - 4.5.11 and 5.0.0 - 5.0.5. | 0.0.0 - 3.4.194.0.0 - 4.3.164.4.0 - 4.4.14 +2 more | High |
AIKIDO-2026-11180 spring-data-mongodb is vulnerable to Improper Neutralization of Special Elements in Data Query Logic in versions 0.0.0 - 3.4.19, 4.0.0 - 4.3.16, 4.4.0 - 4.4.14, 4.5.0 - 4.5.11 and 5.0.0 - 5.0.5. | 0.0.0 - 3.4.194.0.0 - 4.3.164.4.0 - 4.4.14 +2 more | Medium |
CVE-2022-22980 org.springframework.data:spring-data-mongodb is vulnerable to Improper Neutralization of Special Elements used in an Expression Language Statement ('Expression Language Injection') in versions 3.4.0 - 3.4.0 and 0.0.0 - 3.3.5. | 0.0.0 - 3.3.53.4.0 - 3.4.0 | Critical |
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
org.mongodb:mongodb-driver-core Version * | — | — |
org.mongodb:mongodb-driver-sync Version * | — | — |
org.mongodb:mongodb-driver-reactivestreams Version * | — | — |
org.mongodb:mongodb-crypt Version * | — | — |
org.springframework:spring-tx Version * | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant