StackRadar

CVE-2026-41721

Medium

Advisory

Published 10 Jun 2026In the index since 6 Sept 2026
Severity
Medium
worst across findings
CVSS
5.9
base score, highest
EPSS
0.003
26th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
155
of 17,781 indexed, latest versions
Container images
157
deployed by those charts
Fix available
1 of 1
affected package

Spring Data Commons: Denial of Service via excessive memory allocation in projection binding

Carried by container images the latest versions of 155 of 17,781 indexed charts deploy, on 157 images.

Affected packageAffected versionsFixed inImages
spring-data-commonsmaven1.12.2.RELEASE, 1.12.4.RELEASE, 1.13.14.RELEASE, 1.13.16.RELEASE+73 more3.5.12, 4.0.6157
OSV records
GHSA-5m4m-73w9-8433

Charts affected

155 by stars
ChartLatestAffected imagesRadar Score
webapp-db-javawebapp-db-java-repo0.1.01 of 2See more

webapp-db-java webapp-db-java-repo 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-41721.

Container imageDigestPackageFixed in
arturisimo/webapp-db-java:v2c95524e90b57
spring-data-commons@2.6.1
no fix listed

Open the chart page →

2,566
webhookiewebhookie0.1.21 of 1See more

webhookie webhookie 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-41721.

Container imageDigestPackageFixed in
hookiesolutions/webhookie:latest0629694246ba
spring-data-commons@2.6.1
no fix listed

Open the chart page →

14,364
webhookie-allwebhookie0.1.21 of 3See more

webhookie-all webhookie 0.1.2

1 of the 3 container images this version deploys carry CVE-2026-41721.

Container imageDigestPackageFixed in
hookiesolutions/webhookie:latest0629694246ba
spring-data-commons@2.6.1
no fix listed

Open the chart page →

28,605
workshop-pipelinesworkshop-pipelines0.1.61 of 2See more

workshop-pipelines workshop-pipelines 0.1.6

1 of the 2 container images this version deploys carry CVE-2026-41721.

Container imageDigestPackageFixed in
quay.io/maximilianopizarro/workshop-pipelines:lateste383ba3e0966
spring-data-commons@3.2.0
no fix listed

Open the chart page →

11,577
zahori-serverzahoriVerified publisher1.0.11 of 2See more

zahori-server zahori 1.0.1

1 of the 2 container images this version deploys carry CVE-2026-41721.

Container imageDigestPackageFixed in
zahoriaut/zahori-server:0.1.17b2de13916f3e
spring-data-commons@2.7.7
no fix listed

Open the chart page →

5,846

Container images carrying it

157 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
fjvela/urjc-fjvela-worker:1.0.170cebf67bd66
spring-data-commons@2.2.1.RELEASE
no fix listed
1
folioci/mod-data-export:latest0cc86bf09755
spring-data-commons@4.0.2
4.0.6
1
folioci/mod-data-export-spring:latestf1d7caf4544b
spring-data-commons@4.0.2
4.0.6
1
folioci/mod-data-export-worker:latest1ad1811c9b37
spring-data-commons@4.0.2
4.0.6
1
folioci/mod-ldp:latestb55696fd9065
spring-data-commons@3.2.4
no fix listed
1
gdrocha/togglr-backend:1.0.0d5ae64e83d4c
spring-data-commons@3.1.5
no fix listed
1
geonetwork/gn-cloud-ogc-api-records-service:4.2.8-020c9bb761f67
spring-data-commons@2.3.6.RELEASE
no fix listed
1
golenski/fibonacci-msg-relay:1.0.0c863dcb0c513
spring-data-commons@3.3.5
no fix listed
1
golenski/fibonacci-task-manager:2.0.03a2b36df247b
spring-data-commons@3.3.5
no fix listed
1
golenski/fibonacci-worker:2.0.0954caf4aaf6a
spring-data-commons@3.3.5
no fix listed
1
gotson/komga:0.99.49b15ea6bfc30
spring-data-commons@2.5.1
no fix listed
1
gotson/komga:1.22.0ba892ab3e082
spring-data-commons@3.4.0
no fix listed
1
graviteeio/am-gateway:4.12.607b7f6dc267a
spring-data-commons@3.4.5
no fix listed
1
graviteeio/am-management-api:4.12.6a8eb04ee0c70
spring-data-commons@3.4.5
no fix listed
1
gridgain/cloud-connector:2025.5.15ab838d7d3cb
spring-data-commons@3.5.8
3.5.12
1
gridgain/community:8.9.11d32d182a0e6a
spring-data-commons@2.2.13.RELEASE
no fix listed
1
gurolakman/smsf-configuration:1.0.49abb3882bcbd
spring-data-commons@2.6.3
no fix listed
1
gurolakman/ussigw-configuration:1.0.4bf18525c5ad9
spring-data-commons@2.6.3
no fix listed
1
hugohg34/toposervice:0.0.2812a03b3f274
spring-data-commons@2.6.0
no fix listed
1
intelloop/atlas-cmms-backend:v1.5.14c61bc3dd3f8
spring-data-commons@3.2.3
no fix listed
1
jacobalberty/unifi:v7.1.664a3616625dda
spring-data-commons@1.13.23.RELEASE
no fix listed
1
jacobalberty/unifi:v7.4.162b3edc809a3ff
spring-data-commons@2.7.2
no fix listed
1
jhipster/jhipster-registry:latest7184525acd4d
spring-data-commons@2.7.2
no fix listed
1
jingking/geonetwork-hnap:4.2.843e74ab234e1
spring-data-commons@2.2.13.RELEASE
no fix listed
1
kimb88/hello-world-spring-boot:latest0639155241cb
spring-data-commons@2.0.9.RELEASE
no fix listed
1
kvalitetsit/stakit-backend:0.3.0f0af0ba589af
spring-data-commons@3.3.0
no fix listed
1
ladeit/ladeit:latest962b665ffe82
spring-data-commons@2.1.3.RELEASE
no fix listed
1
lavandadelpatio/automated-download-films:0.0.2094e225a5a6f8
spring-data-commons@2.3.4.RELEASE
no fix listed
1
lavandadelpatio/automated-download-shows:0.0.492de3c3426d2
spring-data-commons@2.3.4.RELEASE
no fix listed
1
lavandadelpatio/filebot:0.0.671f2ccec8c0d
spring-data-commons@2.4.6
no fix listed
1
lavandadelpatio/filebot-bot:0.0.1-SNAPSHOTd2cba20aa4d8
spring-data-commons@2.6.0
no fix listed
1
lavandadelpatio/torznab-atomohd:latest214eaef5444c
spring-data-commons@3.0.4
no fix listed
1
linuxserver/airsonic-advanced:11.1.4d286a7f55a59
spring-data-commons@3.3.3
no fix listed
1
linuxserver/unifi-controller:8.0.240ae315a3a456
spring-data-commons@2.7.2
no fix listed
1
linuxserver/unifi-controller:7.3.83ab105cc50322
spring-data-commons@1.13.23.RELEASE
no fix listed
1
linuxserver/unifi-network-application:10.6.101-ls144b6ce6968ee45
spring-data-commons@3.5.11
3.5.12
1
maksimkavalenka/microservices-learning.resource-processor:latest64a25afb8748
spring-data-commons@3.1.4
no fix listed
1
maksimkavalenka/microservices-learning.resource-service:latest13ad9bb170a0
spring-data-commons@3.1.4
no fix listed
1
maksimkavalenka/microservices-learning.song-service:latest2bcdac368b07
spring-data-commons@3.1.4
no fix listed
1
microcks/microcks:0.8.0e3a3e0c67b09
spring-data-commons@1.13.16.RELEASE
no fix listed
1
openbas/platform:2.0.5d986d80b0a75
spring-data-commons@3.3.7
no fix listed
1
operaton/operaton:1.0.0-beta-4b35867ffe4d8
spring-data-commons@3.4.4
no fix listed
1
platform9community/customers-service:latest2089811e5cc6
spring-data-commons@2.3.1.RELEASE
no fix listed
1
platform9community/vets-service:latestd1165c94dfb3
spring-data-commons@2.3.1.RELEASE
no fix listed
1
platform9community/visits-service:latest8d11b50368c6
spring-data-commons@2.3.1.RELEASE
no fix listed
1
polyakov/hapi-fhir-jpaserver-example:latestdbcef69146b8
spring-data-commons@1.12.4.RELEASE
no fix listed
1
razzy10/product-service:latest702e411956db
spring-data-commons@3.5.3
3.5.12
1
redestroyder/business-service:0.0.1db03499a0726
spring-data-commons@2.6.1
no fix listed
1
refar/apm-api:v5.7.1241373fa2972
spring-data-commons@2.3.2.RELEASE
no fix listed
1
remche/shinyproxy:2.6.18bcda8a04d3b
spring-data-commons@2.5.10
no fix listed
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.