StackRadar

CVE-2026-41717

High

Advisory

Published 10 Jun 2026In the index since 6 Sept 2026
Severity
High
worst across findings
CVSS
8.1
base score, highest
EPSS
0.003
26th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
53
of 17,781 indexed, latest versions
Container images
34
deployed by those charts
Fix available
1 of 1
affected package

Spring Data MongoDB is vulnerable to SpEL (Spring Expression Language) expression injection

Carried by container images the latest versions of 53 of 17,781 indexed charts deploy, on 34 images.

Affected packageAffected versionsFixed inImages
spring-data-mongodbmaven1.9.2.RELEASE, 1.10.16.RELEASE, 1.10.23.RELEASE, 2.0.14.RELEASE+21 more4.5.12, 5.0.634
OSV records
GHSA-5whc-4q84-fj73

Charts affected

53 by stars
ChartLatestAffected imagesRadar Score
wahlrechttwomartensVerified publisher0.3.01 of 1See more

wahlrecht twomartens 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-41717.

Container imageDigestPackageFixed in
2martens/wahlrecht:latestba2c3040dab0
spring-data-mongodb@4.5.2
4.5.12

Open the chart page →

1,689
webhookiewebhookie0.1.21 of 1See more

webhookie webhookie 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-41717.

Container imageDigestPackageFixed in
hookiesolutions/webhookie:latest0629694246ba
spring-data-mongodb@3.3.1
no fix listed

Open the chart page →

14,364
webhookie-allwebhookie0.1.21 of 3See more

webhookie-all webhookie 0.1.2

1 of the 3 container images this version deploys carry CVE-2026-41717.

Container imageDigestPackageFixed in
hookiesolutions/webhookie:latest0629694246ba
spring-data-mongodb@3.3.1
no fix listed

Open the chart page →

28,605

Container images carrying it

34 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
codeurjc/toposervice:v1.0:v1.239fb4c11e6a49
spring-data-mongodb@4.0.0
no fix listed
13
oscarsotosanchez/toposervice:v1.0d4d020e9f272
spring-data-mongodb@3.1.1
no fix listed
4
jacobalberty/unifi:v10.0.162896c0ab82d33
spring-data-mongodb@4.3.13
no fix listed
3
pavanelthepu/todo-api:1.0.2f47658e3b24c
spring-data-mongodb@3.2.2
no fix listed
3
graviteeio/apim-gateway:4.12.19-debian05fd67a93056
spring-data-mongodb@4.4.4
no fix listed
2
graviteeio/apim-management-api:4.12.19-debian27374522cd04
spring-data-mongodb@4.4.4
no fix listed
2
hookiesolutions/webhookie:latest0629694246ba
spring-data-mongodb@3.3.1
no fix listed
2
mbentley/omada-controller:4.3f4e682274bed
spring-data-mongodb@2.0.14.RELEASE
no fix listed
2
stakater/stakater-nordmart-review:1.0.35954d2be66e95
spring-data-mongodb@3.4.2
no fix listed
2
2martens/timetable:latestbd1ba6ab84c9
spring-data-mongodb@4.5.4
4.5.12
1
2martens/wahlrecht:latestba2c3040dab0
spring-data-mongodb@4.5.2
4.5.12
1
apimap/api:v1.8.11ae2b3ab00177
spring-data-mongodb@3.4.5
no fix listed
1
bluerange/bluerange:26.1.307c8f73b55df
spring-data-mongodb@4.4.5
no fix listed
1
cbioportal/cbioportal:6.4.1-web-shenandoah08debbd2dbf9
spring-data-mongodb@4.5.4
4.5.12
1
dellcloud/category:distributed02fc234353a9
spring-data-mongodb@3.0.1.RELEASE
no fix listed
1
fimperato/detected-info-store:1.1.0-RELEASEe32920eedd3a
spring-data-mongodb@3.4.6
no fix listed
1
fimperato/sparkvid-api:1.0.5-RELEASE604012b77841
spring-data-mongodb@3.1.0
no fix listed
1
fimperato/static-src-info-data-transformation:1.0.5-RELEASEdf05c388ea6c
spring-data-mongodb@3.4.6
no fix listed
1
hugohg34/toposervice:0.0.2812a03b3f274
spring-data-mongodb@3.3.0
no fix listed
1
jacobalberty/unifi:v7.1.664a3616625dda
spring-data-mongodb@1.10.23.RELEASE
no fix listed
1
jacobalberty/unifi:v7.4.162b3edc809a3ff
spring-data-mongodb@3.4.2
no fix listed
1
lavandadelpatio/automated-download-films:0.0.2094e225a5a6f8
spring-data-mongodb@3.0.4.RELEASE
no fix listed
1
lavandadelpatio/automated-download-shows:0.0.492de3c3426d2
spring-data-mongodb@3.0.4.RELEASE
no fix listed
1
lavandadelpatio/filebot:0.0.671f2ccec8c0d
spring-data-mongodb@3.1.6
no fix listed
1
lavandadelpatio/filebot-bot:0.0.1-SNAPSHOTd2cba20aa4d8
spring-data-mongodb@3.3.0
no fix listed
1
lavandadelpatio/torznab-atomohd:latest214eaef5444c
spring-data-mongodb@4.0.4
no fix listed
1
linuxserver/unifi-controller:8.0.240ae315a3a456
spring-data-mongodb@3.4.2
no fix listed
1
linuxserver/unifi-controller:7.3.83ab105cc50322
spring-data-mongodb@1.10.23.RELEASE
no fix listed
1
linuxserver/unifi-network-application:10.6.101-ls144b6ce6968ee45
spring-data-mongodb@4.5.11
4.5.12
1
microcks/microcks:0.8.0e3a3e0c67b09
spring-data-mongodb@1.10.16.RELEASE
no fix listed
1
richardchesterwood/k8s-fleetman-position-tracker:release336c43961214c
spring-data-mongodb@1.9.2.RELEASE
no fix listed
1
siakhooi/query:1.0.0f1f4b5b1b870
spring-data-mongodb@5.0.4
5.0.6
1
slagattollas/toposervice-practica:latestdc63973dae0d
spring-data-mongodb@3.1.1
no fix listed
1
thmmniii/fbs-core:v1.27.15438517d9fc2
spring-data-mongodb@3.4.12
no fix listed
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.