CVE-2026-41696Medium· 5.9▾ SunlitSpring Data MongoDB repository query methods annotated with @Query that use regex parameter binding perform insufficient validation of the bound parameter. An attacker can supply a crafted string to break out of the intended regular expr…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 32.5 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 17.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.3%
Spring Data MongoDB repository query methods annotated with @Query that use regex parameter binding perform insufficient validation of the bound parameter. An attacker can supply a crafted string to break out of the intended regular expression quoting.
Affected versions: Spring Data MongoDB 5.0.0 through 5.0.5; 4.5.0 through 4.5.11; 4.4.0 through 4.4.14; 4.3.0 through 4.3.16; 4.2.0 through 4.2.15; 4.1.0 through 4.1.14; 4.0.0 through 4.0.15; 3.4.0 through 3.4.19.
spring_data_mongodb >= 3.4.0, < 3.4.20spring_data_mongodb >= 4.0.0, <= 4.0.15spring_data_mongodb >= 4.1.0, <= 4.1.14spring_data_mongodb >= 4.2.0, <= 4.2.15spring_data_mongodb >= 4.3.0, < 4.3.17spring_data_mongodb >= 4.4.0, < 4.4.15spring_data_mongodb >= 4.5.0, < 4.5.11.1spring_data_mongodb >= 5.0.0, < 5.0.5.1Upgrade past the affected range:
spring_data_mongodb 5.0.5.1Connected by shared product, vendor, weakness, or advisory.
CVE-2026-41717High· 8.1Spring Data MongoDB contains a SpEL (Spring Expression Language) expression injection vulnerability
CVE-2026-59318Medium· 6.5In Spring AI's tool calling support, the per-request tool list is advertised to the model as a boundary but is not fully enforced when a tool call is dispatched
CVE-2026-59308Medium· 4.2In Spring AI's Semantic Cache support, the context hash used to isolate cached responses between different system prompts could allow cached responses to be shared across unrelated contexts. Affected versions: Spring AI: 2.0.0
CVE-2026-59279High· 7.5The MCP Streamable HTTP server transport (WebFlux and WebMvc variants) does not place any limit on the number of sessions it retains, and by default does not require clients to be authenticated
CVE-2026-59310Critical· 9.8vCenter directory-traversal vulnerability
CVE-2026-47880Medium· 5.4A producer who can publish to a JMS destination consumed by any Spring Integration JMS inbound component can set String JMS properties named replyChannel, errorChannel, or json__TypeId__ which are copied verbatim into the Spring Integrat…