Denial of Service Vulnerability in Spring Data Commons Products
CVE-2026-41711
5.9MEDIUM
What is CVE-2026-41711?
Applications utilizing Spring Data Commons are exposed to a potential Denial of Service scenario. This occurs due to improper handling of Sort parameters, which could lead to a StackOverflowException. Developers should review and update their implementations to mitigate this risk. Affected versions vary across multiple releases, including 4.0.x, 3.5.x, 3.4.x, 3.3.x, 3.2.x, 3.1.x, 3.0.x, and 2.7.x, making it essential to check compatibility before deploying patches or updates.
Affected Version(s)
Spring Data Commons 4.0.0 < 4.0.5.1
Spring Data Commons 3.5.0 < 3.5.11.1
Spring Data Commons 3.4.0 < 3.4.15
