← العودة للجدول
CVE-2026-41717
CVE-2026-41717 — Spring Data MongoDB contains a SpEL (Spring Expression Language) expression inje
📅 2026-06-10
🟠 High 🔥 No NVD APT APT CVSS 8.1

📋 الوصف الكامل

Spring Data MongoDB contains a SpEL (Spring Expression Language) expression injection vulnerability. The issue occurs during parameter binding when a user-defined repository query method is annotated with @Query and utilizes a capture-all placeholder. Affected versions: Spring Data MongoDB 5.0.0 through 5.0.5; 4.5.0 through 4.5.11; 4.4.0 through 4.4.14; 4.3.0 through 4.3.16; 4.2.0 through 4.2.15;

💻 الأنظمة المتأثرة

Spring Framework | MongoDB

⚠️ نوع التهديد

APT

🔗 CVE ID

CVE-2026-41717

📡 المصدر

NVD

✅ الحلول والتخفيف

Update to v5.0.0

🔗 المصدر الأصلي ← 📘 NVD ← ⚡ CISA KEV ←