Junglewise Threat Intelligence

CVE-2026-41695: VMware Spring Data Commons denial of service in MappingContext

CVE-2026-41695 · Severity: high · CVSS 7.5 · Published 2026-06-10

Vendors: Spring.

Executive brief

Spring Data Commons, a library used to simplify data access in Java applications, contains a flaw in how it handles certain database query parameters. An attacker can send a large number of specially crafted web requests that cause the application to consume all available memory. This leads to a denial-of-service (DoS) condition where the application crashes or becomes unresponsive, disrupting business operations.

Technical details

The vulnerability exists in `PersistentPropertyPathFactory.java` where an unbounded `ConcurrentHashMap` is used to cache property paths. When `MappingContext.getPersistentPropertyPath` is called with user-supplied strings (such as sort or projection parameters), every unique string—including invalid ones—is stored in the cache indefinitely without eviction. A remote, unauthenticated attacker can exploit this by sending millions of requests with unique, random path strings, eventually exhausting the JVM heap and causing an OutOfMemoryError (OOM). The issue is particularly reachable when using Spring Data REST or store-specific query mappers that pass HTTP-derived strings directly to the mapping context. Patches have been released in versions 4.0.6 and 3.5.12.

Affected products

  • Spring spring-data-commons >= 4.0.0, <= 4.0.5
  • Spring spring-data-commons >= 3.5.0, <= 3.5.11
  • Spring spring-data-commons >= 3.4.0, <= 3.4.13

Timeline

  • 2026-06-09: disclosed
  • 2026-06-10: advisory: NVD publication date
  • 2026-07-31: patched: GitHub Advisory reviewed and updated with patch versions

References