PT-2026-48312 · Vmware · Spring Data Mongodb

CVE-2026-41696

·

Published

2026-06-09

·

Updated

2026-06-22

CVSS v3.1

5.9

Medium

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Spring Data MongoDB versions 5.0.0 through 5.0.5 Spring Data MongoDB versions 4.5.0 through 4.5.11 Spring Data MongoDB versions 4.4.0 through 4.4.14 Spring Data MongoDB versions 4.3.0 through 4.3.16 Spring Data MongoDB versions 4.2.0 through 4.2.15 Spring Data MongoDB versions 4.1.0 through 4.1.14 Spring Data MongoDB versions 4.0.0 through 4.0.15 Spring Data MongoDB versions 3.4.0 through 3.4.19
Description Repository query methods annotated with @Query that utilize regex parameter binding perform insufficient validation of the bound parameter. This allows an attacker to provide a specially crafted string to bypass the intended regular expression quoting.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-41696
GHSA-HC43-M36C-8V33

Affected Products

Spring Data Mongodb