Home
HIGH: 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HDefault status
unaffected
2.7.0 (custom) before 2.7.20
affected
3.3.0 (custom) before 3.3.17
affected
3.4.0 (custom) before 3.4.15
affected
3.5.0 (custom) before 3.5.12
affected
4.0.0 (custom) before 4.0.6
affected
Description
Spring Data's internal property-lookup cache accepts and permanently retains attacker-supplied strings as cache keys, allowing heap exhaustion through repeated requests. Affected versions: Spring Data Commons 2.7.0 through 2.7.19; 3.3.0 through 3.3.16; 3.4.0 through 3.4.14; 3.5.0 through 3.5.11; 4.0.0 through 4.0.5.
Problem types
CWE-770: Allocation of Resources Without Limits or Throttling
Product status
2.7.0 (custom) before 2.7.20
3.3.0 (custom) before 3.3.17
3.4.0 (custom) before 3.4.15
3.5.0 (custom) before 3.5.12
4.0.0 (custom) before 4.0.6
References
spring.io/security/cve-2026-41716