StackRadar

CVE-2026-41717

High

Advisory

Published 10 Jun 2026In the index since 6 Sept 2026
Severity
High
worst across findings
CVSS
8.1
base score, highest
EPSS
0.003
26th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
53
of 17,781 indexed, latest versions
Container images
34
deployed by those charts
Fix available
1 of 1
affected package

Spring Data MongoDB is vulnerable to SpEL (Spring Expression Language) expression injection

Carried by container images the latest versions of 53 of 17,781 indexed charts deploy, on 34 images.

Affected packageAffected versionsFixed inImages
spring-data-mongodbmaven1.9.2.RELEASE, 1.10.16.RELEASE, 1.10.23.RELEASE, 2.0.14.RELEASE+21 more4.5.12, 5.0.634
OSV records
GHSA-5whc-4q84-fj73

Charts affected

53 by stars
ChartLatestAffected imagesRadar Score
apim3graviteeioVerified publisher4.12.192 of 4See more

apim3 graviteeio 4.12.19

2 of the 4 container images this version deploys carry CVE-2026-41717.

Container imageDigestPackageFixed in
graviteeio/apim-gateway:4.12.19-debian05fd67a93056
spring-data-mongodb@4.4.4
no fix listed
graviteeio/apim-management-api:4.12.19-debian27374522cd04
spring-data-mongodb@4.4.4
no fix listed

Open the chart page →

4,806
microcksmicrocksOfficialVerified publisher0.8.0-helm-3.kube-1.171 of 5See more

microcks microcks 0.8.0-helm-3.kube-1.17

1 of the 5 container images this version deploys carry CVE-2026-41717.

Container imageDigestPackageFixed in
microcks/microcks:0.8.0e3a3e0c67b09
spring-data-mongodb@1.10.16.RELEASE
no fix listed

Open the chart page →

10,732
unifiunifiVerified publisher1.16.01 of 1See more

unifi unifi 1.16.0

1 of the 1 container images this version deploys carry CVE-2026-41717.

Container imageDigestPackageFixed in
jacobalberty/unifi:v10.0.162896c0ab82d33
spring-data-mongodb@4.3.13
no fix listed

Open the chart page →

7,268
unifi-controllerqonstruktVerified publisher2.6.11 of 1See more

unifi-controller qonstrukt 2.6.1

1 of the 1 container images this version deploys carry CVE-2026-41717.

Container imageDigestPackageFixed in
linuxserver/unifi-controller:8.0.240ae315a3a456
spring-data-mongodb@3.4.2
no fix listed

Open the chart page →

10,469
unifigeek-cookbookVerified publisher5.1.31 of 1See more

unifi geek-cookbook 5.1.3

1 of the 1 container images this version deploys carry CVE-2026-41717.

Container imageDigestPackageFixed in
jacobalberty/unifi:v7.4.162b3edc809a3ff
spring-data-mongodb@3.4.2
no fix listed

Open the chart page →

11,839
apimgraviteeioVerified publisher4.12.192 of 4See more

apim graviteeio 4.12.19

2 of the 4 container images this version deploys carry CVE-2026-41717.

Container imageDigestPackageFixed in
graviteeio/apim-gateway:4.12.19-debian05fd67a93056
spring-data-mongodb@4.4.4
no fix listed
graviteeio/apim-management-api:4.12.19-debian27374522cd04
spring-data-mongodb@4.4.4
no fix listed

Open the chart page →

4,806
feedbacksystemthm-mni-iiVerified publisher0.47.11 of 10See more

feedbacksystem thm-mni-ii 0.47.1

1 of the 10 container images this version deploys carry CVE-2026-41717.

Container imageDigestPackageFixed in
thmmniii/fbs-core:v1.27.15438517d9fc2
spring-data-mongodb@3.4.12
no fix listed

Open the chart page →

28,534
cbioportalcbioportalOfficialVerified publisher1.1.01 of 1See more

cbioportal cbioportal 1.1.0

1 of the 1 container images this version deploys carry CVE-2026-41717.

Container imageDigestPackageFixed in
cbioportal/cbioportal:6.4.1-web-shenandoah08debbd2dbf9
spring-data-mongodb@4.5.4
4.5.12

Open the chart page →

3,674
omada-controllergeek-cookbookVerified publisher4.4.21 of 1See more

omada-controller geek-cookbook 4.4.2

1 of the 1 container images this version deploys carry CVE-2026-41717.

Container imageDigestPackageFixed in
mbentley/omada-controller:4.3f4e682274bed
spring-data-mongodb@2.0.14.RELEASE
no fix listed

Open the chart page →

11,553
todo-apipavanelthepu0.1.01 of 2See more

todo-api pavanelthepu 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-41717.

Container imageDigestPackageFixed in
pavanelthepu/todo-api:1.0.2f47658e3b24c
spring-data-mongodb@3.2.2
no fix listed

Open the chart page →

2,544
querysiakhooiVerified publisher1.0.01 of 1See more

query siakhooi 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-41717.

Container imageDigestPackageFixed in
siakhooi/query:1.0.0f1f4b5b1b870
spring-data-mongodb@5.0.4
5.0.6

Open the chart page →

1,792
omada-controllerandrelote-k8sVerified publisher4.5.01 of 1See more

omada-controller andrelote-k8s 4.5.0

1 of the 1 container images this version deploys carry CVE-2026-41717.

Container imageDigestPackageFixed in
mbentley/omada-controller:4.3f4e682274bed
spring-data-mongodb@2.0.14.RELEASE
no fix listed

Open the chart page →

11,553
apimap-apiapimapOfficialVerified publisher1.8.111 of 1See more

apimap-api apimap 1.8.11

1 of the 1 container images this version deploys carry CVE-2026-41717.

Container imageDigestPackageFixed in
apimap/api:v1.8.11ae2b3ab00177
spring-data-mongodb@3.4.5
no fix listed

Open the chart page →

2,231
chart-app-vidapp-vid-chartVerified publisher0.0.71 of 2See more

chart-app-vid app-vid-chart 0.0.7

1 of the 2 container images this version deploys carry CVE-2026-41717.

Container imageDigestPackageFixed in
fimperato/sparkvid-api:1.0.5-RELEASE604012b77841
spring-data-mongodb@3.1.0
no fix listed

Open the chart page →

8,866
bluerange-serverbluerangeOfficialVerified publisher1.3.11 of 1See more

bluerange-server bluerange 1.3.1

1 of the 1 container images this version deploys carry CVE-2026-41717.

Container imageDigestPackageFixed in
bluerange/bluerange:26.1.307c8f73b55df
spring-data-mongodb@4.4.5
no fix listed

Open the chart page →

1,816
category-microservicebusi-adsVerified publisher1.0.01 of 2See more

category-microservice busi-ads 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-41717.

Container imageDigestPackageFixed in
dellcloud/category:distributed02fc234353a9
spring-data-mongodb@3.0.1.RELEASE
no fix listed

Open the chart page →

11,869
eoloplannerdfa-amm-eoloplannerVerified publisher0.1.01 of 7See more

eoloplanner dfa-amm-eoloplanner 0.1.0

1 of the 7 container images this version deploys carry CVE-2026-41717.

Container imageDigestPackageFixed in
oscarsotosanchez/toposervice:v1.0d4d020e9f272
spring-data-mongodb@3.1.1
no fix listed

Open the chart page →

27,550
eoloplannerdreyg-jescribanob-chart-eoloplanner0.1.01 of 7See more

eoloplanner dreyg-jescribanob-chart-eoloplanner 0.1.0

1 of the 7 container images this version deploys carry CVE-2026-41717.

Container imageDigestPackageFixed in
oscarsotosanchez/toposervice:v1.0d4d020e9f272
spring-data-mongodb@3.1.1
no fix listed

Open the chart page →

24,656
unifiegebackVerified publisher2.1.61 of 1See more

unifi egeback 2.1.6

1 of the 1 container images this version deploys carry CVE-2026-41717.

Container imageDigestPackageFixed in
jacobalberty/unifi:v10.0.162896c0ab82d33
spring-data-mongodb@4.3.13
no fix listed

Open the chart page →

7,268
eolicplantseolicplantsVerified publisher0.1.01 of 7See more

eolicplants eolicplants 0.1.0

1 of the 7 container images this version deploys carry CVE-2026-41717.

Container imageDigestPackageFixed in
oscarsotosanchez/toposervice:v1.0d4d020e9f272
spring-data-mongodb@3.1.1
no fix listed

Open the chart page →

27,291
eoloPlanteolo-plannerVerified publisher0.1.01 of 7See more

eoloPlant eolo-planner 0.1.0

1 of the 7 container images this version deploys carry CVE-2026-41717.

Container imageDigestPackageFixed in
codeurjc/toposervice:v1.239fb4c11e6a49
spring-data-mongodb@4.0.0
no fix listed

Open the chart page →

27,537
eoloplannereoloplannerVerified publisher0.1.01 of 7See more

eoloplanner eoloplanner 0.1.0

1 of the 7 container images this version deploys carry CVE-2026-41717.

Container imageDigestPackageFixed in
codeurjc/toposervice:v1.09fb4c11e6a49
spring-data-mongodb@4.0.0
no fix listed

Open the chart page →

32,205
eoloPlannerCommunicationsKubernetes3eoloplannercommunicationskuberneteshelmVerified publisher0.1.01 of 7See more

eoloPlannerCommunicationsKubernetes3 eoloplannercommunicationskuberneteshelm 0.1.0

1 of the 7 container images this version deploys carry CVE-2026-41717.

Container imageDigestPackageFixed in
codeurjc/toposervice:v1.239fb4c11e6a49
spring-data-mongodb@4.0.0
no fix listed

Open the chart page →

27,537
eoloplanner-mcaeoloplanner-mcaVerified publisher0.1.01 of 7See more

eoloplanner-mca eoloplanner-mca 0.1.0

1 of the 7 container images this version deploys carry CVE-2026-41717.

Container imageDigestPackageFixed in
oscarsotosanchez/toposervice:v1.0d4d020e9f272
spring-data-mongodb@3.1.1
no fix listed

Open the chart page →

27,256
eoloplannereoloplanner-molynx-gat0.1.01 of 7See more

eoloplanner eoloplanner-molynx-gat 0.1.0

1 of the 7 container images this version deploys carry CVE-2026-41717.

Container imageDigestPackageFixed in
codeurjc/toposervice:v1.09fb4c11e6a49
spring-data-mongodb@4.0.0
no fix listed

Open the chart page →

28,482
eolo-plannereolo-planner-repo0.1.01 of 7See more

eolo-planner eolo-planner-repo 0.1.0

1 of the 7 container images this version deploys carry CVE-2026-41717.

Container imageDigestPackageFixed in
codeurjc/toposervice:v1.09fb4c11e6a49
spring-data-mongodb@4.0.0
no fix listed

Open the chart page →

27,096
eoloplanteoloplant1.0.01 of 7See more

eoloplant eoloplant 1.0.0

1 of the 7 container images this version deploys carry CVE-2026-41717.

Container imageDigestPackageFixed in
codeurjc/toposervice:v1.239fb4c11e6a49
spring-data-mongodb@4.0.0
no fix listed

Open the chart page →

27,537
eoloplantseoloplants-urjcVerified publisher0.1.01 of 7See more

eoloplants eoloplants-urjc 0.1.0

1 of the 7 container images this version deploys carry CVE-2026-41717.

Container imageDigestPackageFixed in
codeurjc/toposervice:v1.09fb4c11e6a49
spring-data-mongodb@4.0.0
no fix listed

Open the chart page →

27,721
servereoloserverVerified publisher0.1.01 of 7See more

server eoloserver 0.1.0

1 of the 7 container images this version deploys carry CVE-2026-41717.

Container imageDigestPackageFixed in
codeurjc/toposervice:v1.09fb4c11e6a49
spring-data-mongodb@4.0.0
no fix listed

Open the chart page →

32,205
my-chartfleet-web-app0.1.01 of 6See more

my-chart fleet-web-app 0.1.0

1 of the 6 container images this version deploys carry CVE-2026-41717.

Container imageDigestPackageFixed in
richardchesterwood/k8s-fleetman-position-tracker:release336c43961214c
spring-data-mongodb@1.9.2.RELEASE
no fix listed

Open the chart page →

24,296
todo-apihelm-repo-sharif0.1.01 of 2See more

todo-api helm-repo-sharif 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-41717.

Container imageDigestPackageFixed in
pavanelthepu/todo-api:1.0.2f47658e3b24c
spring-data-mongodb@3.2.2
no fix listed

Open the chart page →

2,544
eoloplanthttpd-eoloplant0.1.01 of 7See more

eoloplant httpd-eoloplant 0.1.0

1 of the 7 container images this version deploys carry CVE-2026-41717.

Container imageDigestPackageFixed in
codeurjc/toposervice:v1.09fb4c11e6a49
spring-data-mongodb@4.0.0
no fix listed

Open the chart page →

32,205
eoloserverihuertas2021-vmartinp2021-helm0.1.01 of 7See more

eoloserver ihuertas2021-vmartinp2021-helm 0.1.0

1 of the 7 container images this version deploys carry CVE-2026-41717.

Container imageDigestPackageFixed in
codeurjc/toposervice:v1.09fb4c11e6a49
spring-data-mongodb@4.0.0
no fix listed

Open the chart page →

27,721
unifik8sonlabVerified publisher0.3.71 of 1See more

unifi k8sonlab 0.3.7

1 of the 1 container images this version deploys carry CVE-2026-41717.

Container imageDigestPackageFixed in
jacobalberty/unifi:v10.0.162896c0ab82d33
spring-data-mongodb@4.3.13
no fix listed

Open the chart page →

7,268
filebot-botluiscajl0.0.111 of 1See more

filebot-bot luiscajl 0.0.11

1 of the 1 container images this version deploys carry CVE-2026-41717.

Container imageDigestPackageFixed in
lavandadelpatio/filebot-bot:0.0.1-SNAPSHOTd2cba20aa4d8
spring-data-mongodb@3.3.0
no fix listed

Open the chart page →

3,679
lavandaluiscajl0.0.1343 of 5See more

lavanda luiscajl 0.0.134

3 of the 5 container images this version deploys carry CVE-2026-41717.

Container imageDigestPackageFixed in
lavandadelpatio/automated-download-films:0.0.2094e225a5a6f8
spring-data-mongodb@3.0.4.RELEASE
no fix listed
lavandadelpatio/automated-download-shows:0.0.492de3c3426d2
spring-data-mongodb@3.0.4.RELEASE
no fix listed
lavandadelpatio/filebot:0.0.671f2ccec8c0d
spring-data-mongodb@3.1.6
no fix listed

Open the chart page →

18,248
torznab-atomohdluiscajl0.0.31 of 1See more

torznab-atomohd luiscajl 0.0.3

1 of the 1 container images this version deploys carry CVE-2026-41717.

Container imageDigestPackageFixed in
lavandadelpatio/torznab-atomohd:latest214eaef5444c
spring-data-mongodb@4.0.4
no fix listed

Open the chart page →

3,290
eoloplantmca-eoloplaner0.1.01 of 7See more

eoloplant mca-eoloplaner 0.1.0

1 of the 7 container images this version deploys carry CVE-2026-41717.

Container imageDigestPackageFixed in
hugohg34/toposervice:0.0.2812a03b3f274
spring-data-mongodb@3.3.0
no fix listed

Open the chart page →

29,588
unifimidokura-communityVerified publisher0.0.61 of 1See more

unifi midokura-community 0.0.6

1 of the 1 container images this version deploys carry CVE-2026-41717.

Container imageDigestPackageFixed in
linuxserver/unifi-controller:7.3.83ab105cc50322
spring-data-mongodb@1.10.23.RELEASE
no fix listed

Open the chart page →

11,188
Practica_4_helmmy-heml-appVerified publisher0.1.01 of 7See more

Practica_4_helm my-heml-app 0.1.0

1 of the 7 container images this version deploys carry CVE-2026-41717.

Container imageDigestPackageFixed in
codeurjc/toposervice:v1.09fb4c11e6a49
spring-data-mongodb@4.0.0
no fix listed

Open the chart page →

27,721
p4p40.1.01 of 7See more

p4 p4 0.1.0

1 of the 7 container images this version deploys carry CVE-2026-41717.

Container imageDigestPackageFixed in
codeurjc/toposervice:v1.239fb4c11e6a49
spring-data-mongodb@4.0.0
no fix listed

Open the chart page →

27,537
todo-apipb-todo-api-v10.1.01 of 2See more

todo-api pb-todo-api-v1 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-41717.

Container imageDigestPackageFixed in
pavanelthepu/todo-api:1.0.2f47658e3b24c
spring-data-mongodb@3.2.2
no fix listed

Open the chart page →

2,544
Practica_4_helmpr04helm0.1.01 of 7See more

Practica_4_helm pr04helm 0.1.0

1 of the 7 container images this version deploys carry CVE-2026-41717.

Container imageDigestPackageFixed in
codeurjc/toposervice:v1.09fb4c11e6a49
spring-data-mongodb@4.0.0
no fix listed

Open the chart page →

27,558
practica-helmpractica-helm0.1.01 of 7See more

practica-helm practica-helm 0.1.0

1 of the 7 container images this version deploys carry CVE-2026-41717.

Container imageDigestPackageFixed in
slagattollas/toposervice-practica:latestdc63973dae0d
spring-data-mongodb@3.1.1
no fix listed

Open the chart page →

28,484
unifiqaoruVerified publisher1.1.21 of 2See more

unifi qaoru 1.1.2

1 of the 2 container images this version deploys carry CVE-2026-41717.

Container imageDigestPackageFixed in
linuxserver/unifi-network-application:10.6.101-ls144b6ce6968ee45
spring-data-mongodb@4.5.11
4.5.12

Open the chart page →

3,642
nordmart-reviewstakaterVerified publisher0.0.61 of 3See more

nordmart-review stakater 0.0.6

1 of the 3 container images this version deploys carry CVE-2026-41717.

Container imageDigestPackageFixed in
stakater/stakater-nordmart-review:1.0.35954d2be66e95
spring-data-mongodb@3.4.2
no fix listed

Open the chart page →

11,554
nordmart-review-instancestakaterVerified publisher1.0.01 of 3See more

nordmart-review-instance stakater 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-41717.

Container imageDigestPackageFixed in
stakater/stakater-nordmart-review:1.0.35954d2be66e95
spring-data-mongodb@3.4.2
no fix listed

Open the chart page →

11,554
unifistartechnicaVerified publisher0.1.31 of 2See more

unifi startechnica 0.1.3

1 of the 2 container images this version deploys carry CVE-2026-41717.

Container imageDigestPackageFixed in
jacobalberty/unifi:v7.1.664a3616625dda
spring-data-mongodb@1.10.23.RELEASE
no fix listed

Open the chart page →

14,493
static-src-people-detector-appstatic-src-people-detector-chartVerified publisher1.5.52 of 6See more

static-src-people-detector-app static-src-people-detector-chart 1.5.5

2 of the 6 container images this version deploys carry CVE-2026-41717.

Container imageDigestPackageFixed in
fimperato/detected-info-store:1.1.0-RELEASEe32920eedd3a
spring-data-mongodb@3.4.6
no fix listed
fimperato/static-src-info-data-transformation:1.0.5-RELEASEdf05c388ea6c
spring-data-mongodb@3.4.6
no fix listed

Open the chart page →

13,646
timetabletwomartensVerified publisher0.2.01 of 1See more

timetable twomartens 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-41717.

Container imageDigestPackageFixed in
2martens/timetable:latestbd1ba6ab84c9
spring-data-mongodb@4.5.4
4.5.12

Open the chart page →

1,527

Container images carrying it

34 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
codeurjc/toposervice:v1.0:v1.239fb4c11e6a49
spring-data-mongodb@4.0.0
no fix listed
13
oscarsotosanchez/toposervice:v1.0d4d020e9f272
spring-data-mongodb@3.1.1
no fix listed
4
jacobalberty/unifi:v10.0.162896c0ab82d33
spring-data-mongodb@4.3.13
no fix listed
3
pavanelthepu/todo-api:1.0.2f47658e3b24c
spring-data-mongodb@3.2.2
no fix listed
3
graviteeio/apim-gateway:4.12.19-debian05fd67a93056
spring-data-mongodb@4.4.4
no fix listed
2
graviteeio/apim-management-api:4.12.19-debian27374522cd04
spring-data-mongodb@4.4.4
no fix listed
2
hookiesolutions/webhookie:latest0629694246ba
spring-data-mongodb@3.3.1
no fix listed
2
mbentley/omada-controller:4.3f4e682274bed
spring-data-mongodb@2.0.14.RELEASE
no fix listed
2
stakater/stakater-nordmart-review:1.0.35954d2be66e95
spring-data-mongodb@3.4.2
no fix listed
2
2martens/timetable:latestbd1ba6ab84c9
spring-data-mongodb@4.5.4
4.5.12
1
2martens/wahlrecht:latestba2c3040dab0
spring-data-mongodb@4.5.2
4.5.12
1
apimap/api:v1.8.11ae2b3ab00177
spring-data-mongodb@3.4.5
no fix listed
1
bluerange/bluerange:26.1.307c8f73b55df
spring-data-mongodb@4.4.5
no fix listed
1
cbioportal/cbioportal:6.4.1-web-shenandoah08debbd2dbf9
spring-data-mongodb@4.5.4
4.5.12
1
dellcloud/category:distributed02fc234353a9
spring-data-mongodb@3.0.1.RELEASE
no fix listed
1
fimperato/detected-info-store:1.1.0-RELEASEe32920eedd3a
spring-data-mongodb@3.4.6
no fix listed
1
fimperato/sparkvid-api:1.0.5-RELEASE604012b77841
spring-data-mongodb@3.1.0
no fix listed
1
fimperato/static-src-info-data-transformation:1.0.5-RELEASEdf05c388ea6c
spring-data-mongodb@3.4.6
no fix listed
1
hugohg34/toposervice:0.0.2812a03b3f274
spring-data-mongodb@3.3.0
no fix listed
1
jacobalberty/unifi:v7.1.664a3616625dda
spring-data-mongodb@1.10.23.RELEASE
no fix listed
1
jacobalberty/unifi:v7.4.162b3edc809a3ff
spring-data-mongodb@3.4.2
no fix listed
1
lavandadelpatio/automated-download-films:0.0.2094e225a5a6f8
spring-data-mongodb@3.0.4.RELEASE
no fix listed
1
lavandadelpatio/automated-download-shows:0.0.492de3c3426d2
spring-data-mongodb@3.0.4.RELEASE
no fix listed
1
lavandadelpatio/filebot:0.0.671f2ccec8c0d
spring-data-mongodb@3.1.6
no fix listed
1
lavandadelpatio/filebot-bot:0.0.1-SNAPSHOTd2cba20aa4d8
spring-data-mongodb@3.3.0
no fix listed
1
lavandadelpatio/torznab-atomohd:latest214eaef5444c
spring-data-mongodb@4.0.4
no fix listed
1
linuxserver/unifi-controller:8.0.240ae315a3a456
spring-data-mongodb@3.4.2
no fix listed
1
linuxserver/unifi-controller:7.3.83ab105cc50322
spring-data-mongodb@1.10.23.RELEASE
no fix listed
1
linuxserver/unifi-network-application:10.6.101-ls144b6ce6968ee45
spring-data-mongodb@4.5.11
4.5.12
1
microcks/microcks:0.8.0e3a3e0c67b09
spring-data-mongodb@1.10.16.RELEASE
no fix listed
1
richardchesterwood/k8s-fleetman-position-tracker:release336c43961214c
spring-data-mongodb@1.9.2.RELEASE
no fix listed
1
siakhooi/query:1.0.0f1f4b5b1b870
spring-data-mongodb@5.0.4
5.0.6
1
slagattollas/toposervice-practica:latestdc63973dae0d
spring-data-mongodb@3.1.1
no fix listed
1
thmmniii/fbs-core:v1.27.15438517d9fc2
spring-data-mongodb@3.4.12
no fix listed
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.