7 Total advisories
7 Vulnerabilities
0 Malware
Dependency scanning
Check whether org.springframework.data:spring-data-commons is in your codebase
Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.
Vulnerabilities
HIGH 7.5
CVE-2026-41695
Spring Data: Unbounded property-path cache keyed by externally-supplied path string
MEDIUM 5.9
CVE-2026-41711
Spring Data Commons: StackOverflowException when parsing Sort parameters (DoS)
MEDIUM 5.9
CVE-2026-41721
Spring Data Commons: Denial of Service via excessive memory allocation in projection binding
HIGH 7.5
CVE-2026-41716
Spring Data Commons: Heap exhaustion from unbounded property-lookup cache retaining crafted string keys
CRITICAL 9.8
CVE-2018-1273
Spring Data Commons remote code injection vulnerability
HIGH 7.5
CVE-2018-1274
Spring Data Commons contain a property path parser vulnerability caused by unlimited resource allocation
HIGH 7.5
CVE-2018-1259
Spring Data Commons, used in combination with XMLBeam, contains a property binder vulnerability caused by improper restriction of XML external entity references
Browse more Maven advisories
Learn What is SAST?
Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →
Ready to move
Start Securing
Free, no credit card | First findings in minutes