maven package report

Is com.baomidou:dynamic-datasource-spring safe?

1 known vulnerability, worst severity MODERATE.

cvss
5.3

how bad it is if exploited, out of 10

epss
0.20%

chance of exploitation in the next 30 days

xyz score
not scored

CyberXYZ composite, out of 10

fig. 01 — GHSA-6rmm-pg23-5f8q, the advisory selected below

// advisories

GHSA-6rmm-pg23-5f8q

MODERATECVE-2026-7045

A vulnerability was determined in baomidou dynamic-datasource 2.5.0. Affected by this vulnerability is the function DsSpelExpressionProcessor#doDetermineDatasource of the file dynamic-datasource-spring/src/main/java/com/baomidou/dynamic/datasource/processor/DsSpelExpressionProcessor.java of the component StandardEvaluationContext/SpelExpressionParser. This manipulation causes injection. The attack

Affected
<= 4.5.0
Fixed in
not stated
Weakness
CWE-74
Published
2026-04-27
Source
github

GHSANVDMITREreferencereferencereferencereferencereferencereferencereference


// ai model usage

Tracked for PyPI packages. HuggingFace models declare Python dependencies, so maven packages are not covered.


Checked 2026-09-22 at 02:38 UTC. The most recent advisory here was published 2026-04-27. Updated continuously from NVD, GHSA, OSV and CNA feeds.

Think a verdict here is wrong? Tell us — we respond within 2 business days.
Is com.baomidou:dynamic-datasource-spring safe? maven package security report | CyberXYZ