StackRadar

CVE-2026-41721

Medium

Advisory

Published 10 Jun 2026In the index since 6 Sept 2026
Severity
Medium
worst across findings
CVSS
5.9
base score, highest
EPSS
0.003
26th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
155
of 17,781 indexed, latest versions
Container images
157
deployed by those charts
Fix available
1 of 1
affected package

Spring Data Commons: Denial of Service via excessive memory allocation in projection binding

Carried by container images the latest versions of 155 of 17,781 indexed charts deploy, on 157 images.

Affected packageAffected versionsFixed inImages
spring-data-commonsmaven1.12.2.RELEASE, 1.12.4.RELEASE, 1.13.14.RELEASE, 1.13.16.RELEASE+73 more3.5.12, 4.0.6157
OSV records
GHSA-5m4m-73w9-8433

Charts affected

155 by stars
ChartLatestAffected imagesRadar Score
webapp-db-javawebapp-db-java-repo0.1.01 of 2See more

webapp-db-java webapp-db-java-repo 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-41721.

Container imageDigestPackageFixed in
arturisimo/webapp-db-java:v2c95524e90b57
spring-data-commons@2.6.1
no fix listed

Open the chart page →

2,566
webhookiewebhookie0.1.21 of 1See more

webhookie webhookie 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-41721.

Container imageDigestPackageFixed in
hookiesolutions/webhookie:latest0629694246ba
spring-data-commons@2.6.1
no fix listed

Open the chart page →

14,364
webhookie-allwebhookie0.1.21 of 3See more

webhookie-all webhookie 0.1.2

1 of the 3 container images this version deploys carry CVE-2026-41721.

Container imageDigestPackageFixed in
hookiesolutions/webhookie:latest0629694246ba
spring-data-commons@2.6.1
no fix listed

Open the chart page →

28,605
workshop-pipelinesworkshop-pipelines0.1.61 of 2See more

workshop-pipelines workshop-pipelines 0.1.6

1 of the 2 container images this version deploys carry CVE-2026-41721.

Container imageDigestPackageFixed in
quay.io/maximilianopizarro/workshop-pipelines:lateste383ba3e0966
spring-data-commons@3.2.0
no fix listed

Open the chart page →

11,577
zahori-serverzahoriVerified publisher1.0.11 of 2See more

zahori-server zahori 1.0.1

1 of the 2 container images this version deploys carry CVE-2026-41721.

Container imageDigestPackageFixed in
zahoriaut/zahori-server:0.1.17b2de13916f3e
spring-data-commons@2.7.7
no fix listed

Open the chart page →

5,846

Container images carrying it

157 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
reportportal/service-api:5.7.29df41f8fb320
spring-data-commons@2.2.5.RELEASE
no fix listed
1
reportportal/service-authorization:5.7.09e73114dbd15
spring-data-commons@2.2.5.RELEASE
no fix listed
1
reportportal/service-jobs:5.7.2dc166c58485a
spring-data-commons@2.4.5
no fix listed
1
richardchesterwood/k8s-fleetman-position-tracker:release336c43961214c
spring-data-commons@1.12.2.RELEASE
no fix listed
1
robotshop/rs-shipping:latest89753ab48919
spring-data-commons@2.3.3.RELEASE
no fix listed
1
salaboy/fmtok8s-monolith:v0.1.0f225568e6d03
spring-data-commons@2.3.2.RELEASE
no fix listed
1
sdandey/dandey-apps:kanban-board-kanban-appbef0f599737b
spring-data-commons@2.1.9.RELEASE
no fix listed
1
seldonio/apife:0.2.7ba81b17f00eb
spring-data-commons@1.13.16.RELEASE
no fix listed
1
seldonio/apife:0.3.1eea0d3f578ca
spring-data-commons@1.13.16.RELEASE
no fix listed
1
siakhooi/query:1.0.0f1f4b5b1b870
spring-data-commons@4.0.4
4.0.6
1
slagattollas/toposervice-practica:latestdc63973dae0d
spring-data-commons@2.4.1
no fix listed
1
slamdev/hetzner-irobo:0.0.13ca20c184c55
spring-data-commons@2.5.5
no fix listed
1
someblackmagic/smtp-fake-server:latest0d63ba37a560
spring-data-commons@2.4.2
no fix listed
1
structurizr/onpremises:2025.11.094b5ffb5119c8
spring-data-commons@3.3.5
no fix listed
1
sysnet4admin/colosseum-agg:logbc25b152d88e
spring-data-commons@3.4.1
no fix listed
1
thingsboard/tb-coap-transport:3.4.1bd45a09d85d9
spring-data-commons@2.7.0
no fix listed
1
thingsboard/tb-http-transport:3.4.1a06f53c5e2da
spring-data-commons@2.7.0
no fix listed
1
thingsboard/tb-mqtt-transport:3.4.1030f316ce301
spring-data-commons@2.7.0
no fix listed
1
thingsboard/tb-node:3.4.1645f43b688f7
spring-data-commons@2.7.0
no fix listed
1
thingsboard/tb-node:3.6.0f40a542832c4
spring-data-commons@2.7.10
no fix listed
1
thingsboard/tb-postgres:latest2d17e4e36edc
spring-data-commons@3.4.10
no fix listed
1
thmmniii/fbs-core:v1.27.15438517d9fc2
spring-data-commons@2.7.12
no fix listed
1
torrespro/mca-worker:2.0.06d3bd305a1ba
spring-data-commons@2.2.1.RELEASE
no fix listed
1
treskon/portrait:DEV-latest88e813f22347
spring-data-commons@3.3.6
no fix listed
1
vitalii1992/account-service:latest0e694d94551d
spring-data-commons@3.1.0
no fix listed
1
vitalii1992/order-service:latest07c4a8833ce4
spring-data-commons@3.1.0
no fix listed
1
vitalii1992/quotes-provider-service:latest44d2d6e00ab3
spring-data-commons@3.1.0
no fix listed
1
vlebediantsev/file-system-ms-final:latest10393a89b4a8
spring-data-commons@2.7.1
no fix listed
1
vlebediantsev/logic-ms:latestdf8bf38c535b
spring-data-commons@2.7.1
no fix listed
1
vlebediantsev/registration-ms-final:latest427af418b75e
spring-data-commons@2.7.1
no fix listed
1
vlebediantsev/user-data-ms-final-final:latest9319437f3c8f
spring-data-commons@2.7.1
no fix listed
1
zahoriaut/zahori-server:0.1.17b2de13916f3e
spring-data-commons@2.7.7
no fix listed
1
zbalogh/reservation-api-server:1.0.97c247e399a1f
spring-data-commons@2.7.3
no fix listed
1
ghcr.io/camunda-community-hub/zeebe-simple-monitor:2.6.2d9d796a1b846
spring-data-commons@3.2.1
no fix listed
1
ghcr.io/curium-rocks/mitre-siphon:main503c00321502
spring-data-commons@3.0.6
no fix listed
1
ghcr.io/eximeebpms/eximeebpms-bpm-platform:run-1.3.0acb8dbce38fd
spring-data-commons@4.0.3
4.0.6
1
ghcr.io/gla-rad/enav-aton-admin-service:latestcf85570b1324
spring-data-commons@4.0.5
4.0.6
1
ghcr.io/gla-rad/enav-aton-service:latest3be878690629
spring-data-commons@4.0.5
4.0.6
1
ghcr.io/gla-rad/enav-aton-service-client:latestf1629ac5f9ec
spring-data-commons@4.0.5
4.0.6
1
ghcr.io/gla-rad/enav-ckeeper:latest415323ef112b
spring-data-commons@4.0.4
4.0.6
1
ghcr.io/gla-rad/enav-vdes-controller:latestc4c52955814f
spring-data-commons@4.0.4
4.0.6
1
ghcr.io/gregperlinli/certvault:2.12.0a7d0cc9e260a
spring-data-commons@3.5.6
3.5.12
1
ghcr.io/it-at-m/kf-app-eai:1.0.65de339b3d537
spring-data-commons@3.5.3
3.5.12
1
ghcr.io/jfwenisch/discord-experiencebot:latestb52ff07f9f0c
spring-data-commons@2.7.3
no fix listed
1
ghcr.io/k8s-at-home/nzbhydra2:v3.14.2ef3670f7e0a8
spring-data-commons@2.3.1.RELEASE
no fix listed
1
ghcr.io/perceptolab/devops-demo-app:0.0.2cdc0658c40fb
spring-data-commons@2.7.3
no fix listed
1
ghcr.io/privacyengineering/hawk-service:latestbfedf47bb5e0
spring-data-commons@3.2.0
no fix listed
1
ghcr.io/radar-base/managementportal/management-portal:3.0.0c1b37e821f72
spring-data-commons@2.7.5
no fix listed
1
ghcr.io/stacksimplify/kube-usermgmt-webapp:1.0.0-mysqldb41b45003c6b6
spring-data-commons@2.1.9.RELEASE
no fix listed
1
ghcr.io/star-whale/server:0.6.158368359c8dd0
spring-data-commons@2.7.6
no fix listed
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.