Junglewise Threat Intelligence

CVE-2026-41716: VMware Spring Data heap exhaustion in property-lookup cache

CVE-2026-41716 · Severity: high · CVSS 7.5 · Published 2026-06-10

Vendors: Spring.

Executive brief

Spring Data Commons, a widely used library for managing data access in Java applications, contains a vulnerability in how it handles internal data caching. An attacker can send specially crafted requests that force the application to store an unlimited amount of data in its memory. Over time, this leads to memory exhaustion, causing the application to slow down significantly or crash entirely, resulting in a denial of service.

Technical details

Spring Data Commons is vulnerable to a Denial of Service (DoS) via heap exhaustion (CWE-770). The vulnerability exists in the internal property-lookup cache, which fails to impose limits on the number or size of entries stored. A remote, unauthenticated attacker can supply crafted strings as cache keys through repeated network requests. Because these keys are retained permanently in the heap without throttling or eviction, the application eventually runs out of memory. The issue is resolved in versions 3.5.12 and 4.0.6.

Affected products

  • Spring Spring Data Commons 2.7.0 through 2.7.19, 3.3.0 through 3.3.16, 3.4.0 through 3.4.14, 3.5.0 through 3.5.11, 4.0.0 through 4.0.5

Timeline

  • 2026-06-10: disclosed
  • 2026-06-10: advisory
  • 2026-08-12: patched

References