Skip to main content

Vendor/product archive

vmware / spring_data_mongodb CVEs

Beta · best-effort

3 CVEs tagged to vmware / spring_data_mongodb1 Critical, 1 High, 1 Medium, 0 Low, 0 Unrated.

CVE-2026-41717

Published Jun 10, 2026

Spring Data MongoDB contains a SpEL (Spring Expression Language) expression injection vulnerability. The issue occurs during parameter binding when a user-defined repository query…

CVSS 8.1 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-41696

Published Jun 10, 2026

Spring Data MongoDB repository query methods annotated with @Query that use regex parameter binding perform insufficient validation of the bound parameter. An attacker can supply…

CVSS 5.9 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2022-22980

Published Jun 23, 2022

A Spring Data MongoDB application is vulnerable to SpEL Injection when using @Query or @Aggregation-annotated query methods with SpEL expressions that contain query parameter plac…

CVSS 9.8 · Critical
Buzz score
7.5
Public PoC observed
Vendor/product tagsBeta · best-effort
Showing 1-3 of 3 CVEsPage 1 of 1