CVE Vulnerability Database

Search and browse 395,856 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-41837MEDIUM5.3Spring Data REST's Querydsl integration accepts arbitrary persistent property paths as request-parameter filter keys and...
CVE-2026-41732HIGH8.1JsonPulsarHeaderMapper matched type headers against trusted packages using a prefix check, meaning that trusting any pac...
CVE-2026-41731HIGH8.1JsonKafkaHeaderMapper and the deprecated DefaultKafkaHeaderMapper matched type headers against trusted packages using a ...
CVE-2026-41730MEDIUM5.3Spring Data REST serializes the full exception cause chain into HTTP error response bodies, potentially exposing persist...
CVE-2026-41729HIGH8.1Spring Data REST is vulnerable to SpEL expression injection through map-typed properties when processing JSON Patch (app...
CVE-2026-41728HIGH7.5Spring Data REST's JSON Patch (application/json-patch+json) implementation does not apply the write-access filter to int...
CVE-2026-41727MEDIUM6.5Spring Kafka's retry topic infrastructure did not sufficiently validate user-controlled header values before acting on t...
CVE-2026-41726MEDIUM6.5When an application opts into DelegatingDeserializer, a producer can grow the consumer's heap without bound by sending r...
CVE-2026-41721MEDIUM5.9Spring Data Commons contains a vulnerability that can lead to a Denial of Service (DoS) condition if Spring Data Web Sup...
CVE-2026-41719MEDIUM6.4A SpEL Injection vulnerability exists in the Spring Data KeyValue if unsanitized user input is passed as Sort into a rep...
CVE-2026-41717HIGH8.1Spring Data MongoDB contains a SpEL (Spring Expression Language) expression injection vulnerability. The issue occurs du...
CVE-2026-41716HIGH7.5Spring Data's internal property-lookup cache accepts and permanently retains attacker-supplied strings as cache keys, al...
CVE-2026-41714MEDIUM4Applications that configure their broker connection via RabbitConnectionFactoryBean.setUri("amqps://...") without also c...
CVE-2026-41711MEDIUM5.9Applications using Spring Data Commons may be vulnerable to a Denial of Service (DoS) attack leading to a StackOverflowE...
CVE-2026-41706MEDIUM6.1Spring Security's CookieRequestCache and CookieServerRequestCache store the pre-authentication request URL in a browser ...
CVE-2026-41701MEDIUM4.4Correlation IDs for replies in the RabbitTemplate.sendAndReceive() with the fixed reply queue are predictable due to int...
CVE-2026-41697MEDIUM4.8Spring Data Relational does not properly escape binding values of externally-controlled input when using StringMatcher (...
CVE-2026-41696MEDIUM5.9Spring Data MongoDB repository query methods annotated with @Query that use regex parameter binding perform insufficient...
CVE-2026-41695HIGH7.5Spring Data Commons applications may be vulnerable to denial of service through resource exhaustion when attacker-contro...
CVE-2026-41694MEDIUM5.3Since Spring Security SAML decrypts SAML Responses as well as elements of SAML LogoutRequests and LogoutResponses withou...
CVE-2026-41008MEDIUM6.1Spring Security Authorization Server's authorization endpoint performs insufficient validation of the request_uri parame...
CVE-2026-41003MEDIUM5.4An attacker able to influence values in RelyingPartyRegistration may be able to run arbitrary code on HTML forms generat...
CVE-2026-40993HIGH7.2An attacker with write permissions to the database table managed by JdbcAssertingPartyMetadataRepository (saml2_assertin...
CVE-2026-40991MEDIUM5.9When using spring-restdocs-webtestclient or spring-restdocs-restassured to document a remote API accessed over HTTP, an ...
CVE-2026-40988HIGH7.5An application using spring-security-saml2-service-provider and the REDIRECT binding for SAML 2.0 Login or Logout may be...