← Vulnerability feed

Vulnerability record · CVE-2018-1274 · published 18 April 2018

CVE-2018-1274: Broadcom spring data commons allocation without limits vulnerability

Broadcom · Spring Data Commons

Spring Data Commons, versions 1.13 to 1.13.10, 2.0 to 2.0.5, and older unsupported versions, contain a property path parser vulnerability caused by unlimited resource allocation. An unauthenticated remote malicious user (or attacker) can issue requests against Spring Data REST endpoints or endpoints using property path parsing which can cause a denial of service (CPU and memory consumption).

7.5 CVSS 3.1 High EPSS 1.9% · top 20.7% CWE-770 · Allocation without limits
7.5CVSS 3.1 base score, v2 5.0
1.9%EPSS exploitation probability, 30 days
NoNot in CISA KEV
3Affected product versions listed by NVD
6References
26 Jun 2026Last modified by NVD

Description

Spring Data Commons, versions 1.13 to 1.13.10, 2.0 to 2.0.5, and older unsupported versions, contain a property path parser vulnerability caused by unlimited resource allocation. An unauthenticated remote malicious user (or attacker) can issue requests against Spring Data REST endpoints or endpoints using property path parsing which can cause a denial of service (CPU and memory consumption).

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Affected products

3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2018-1274 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2018-1273Spring Data Commons property binder allows remote code executionSpring Data Commons fails to properly neutralize special elements in request parameters, allowing crafted input to be bound to object properties. Thi…KEVEPSS 97%analysed9.8CVE-2017-8046Spring Data REST PATCH requests allow remote Java code executionSpring Data REST before 2.6.9 (Ingalls SR9) and before 3.0.1 (Kay SR1), and Spring Boot before 1.5.9 and 2.0 M6, fail to properly validate specially …EPSS 75%analysed8.1CVE-2026-41729Vmware spring data rest expression language injection vulnerabilitySpring Data REST is vulnerable to SpEL expression injection through map-typed properties when processing JSON Patch (application/json-patch+json) req…EPSS 0.40%7.5CVE-2026-41728Vmware spring data rest improper access control vulnerabilitySpring Data REST's JSON Patch (application/json-patch+json) implementation does not apply the write-access filter to intermediate path segments when …EPSS 0.35%7.5CVE-2026-41716Broadcom spring data commons allocation without limits vulnerabilitySpring Data's internal property-lookup cache accepts and permanently retains attacker-supplied strings as cache keys, allowing heap exhaustion throug…EPSS 0.46%7.5CVE-2026-41695Broadcom spring data commons uncontrolled resource consumption vulnerabilitySpring Data Commons applications may be vulnerable to denial of service through resource exhaustion when attacker-controlled property path strings ar…EPSS 0.46%7.5CVE-2018-1259Broadcom spring data commons xml external entity (xxe) vulnerabilitySpring Data Commons, versions 1.13 prior to 1.13.12 and 2.0 prior to 2.0.7, used in combination with XMLBeam 1.4.14 or earlier versions, contains a p…EPSS 4.9%7.1CVE-2026-47849Vmware spring data rest mass assignment vulnerabilitySpring Data REST does not guard identifier (@Id) and version (@Version) properties against mutation via RFC 6902 JSON Patch (application/json-patch+j…EPSS 0.35%

Source: NIST National Vulnerability Database (record CVE-2018-1274), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.