CVE-2026-41721: Spring Data Commons Denial of Service via Data Binding

Published Jun 9, 2026
·
Updated

Spring Data Commons contains a vulnerability that can lead to a Denial of Service (DoS) condition if Spring Data Web Support is enabled in conjunction with a Controller method using @ProjectedPayload, when an attacker sends a specially crafted HTTP request that causes the application to allocate lots of memory.

Affected versions: Spring Data Commons 4.0.0 through 4.0.5; 3.5.0 through 3.5.11; 3.4.0 through 3.4.14; 3.3.0 through 3.3.16; 3.2.0 through 3.2.15; 3.1.0 through 3.1.14; 3.0.0 through 3.0.15; 2.7.0 through 2.7.19.

Affected Software

9 affected components
Spring Spring Data Commons>=4.0.0<=4.0.5, >=3.5.0<=3.5.11, >=3.4.0<=3.4.14, >=3.3.0<=3.3.16, >=3.2.0<=3.2.15, >=3.1.0<=3.1.14, >=3.0.0<=3.0.15, >=2.7.0<=2.7.19
Broadcom Spring Data Commons>=2.7.0<2.7.20
Broadcom Spring Data Commons>=3.0.0<=3.0.15
Broadcom Spring Data Commons>=3.1.0<=3.1.14
Broadcom Spring Data Commons>=3.2.0<=3.2.15
Broadcom Spring Data Commons>=3.3.0<3.3.17
Broadcom Spring Data Commons>=3.4.0<3.4.15
Broadcom Spring Data Commons>=3.5.0<3.5.11.1
Broadcom Spring Data Commons>=4.0.0<4.0.5.1

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Configuration

    Mitigate the Denial of Service condition by ensuring Spring Data Web Support is not enabled when using @ProjectedPayload in controller methods (disable Spring Data Web Support and/or remove @ProjectedPayload usage for affected endpoints).

    Spring Data Web Support Spring Data Web Support (enabled) in conjunction with Controller method using @ProjectedPayload = Disable Spring Data Web Support or avoid using @ProjectedPayload in Controller methods

Event History

Jun 9, 2026
CVE Published
via MITRE·11:48 PM
Data Sourced
via MITRE·11:48 PM
DescriptionSeverityWeakness
Jun 10, 2026
Data Sourced
via NVD·12:16 AM
DescriptionSeverityWeaknessAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2026-41721?

The severity of CVE-2026-41721 is classified as medium with a score of 5.9.

2

What type of vulnerability is CVE-2026-41721?

CVE-2026-41721 is a Denial of Service (DoS) vulnerability in Spring Data Commons.

3

How do I fix CVE-2026-41721?

To fix CVE-2026-41721, ensure that Spring Data Web Support is disabled if not needed for your application.

4

What components are affected by CVE-2026-41721?

CVE-2026-41721 affects Spring Data Commons when used with @ProjectedPayload in Controller methods.

5

What causes CVE-2026-41721 to be exploited?

CVE-2026-41721 can be exploited by an attacker sending specially crafted HTTP requests that lead to resource exhaustion.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203