← Back to CVE List
CVE-2026-41006NVD
Vulnerability Summary
Spring HATEOAS's internal PropertyUtils.createObjectFromProperties method, used by the Collection+JSON and UBER media type deserializers, performs bean property binding via reflection without consulting Jackson access-control annotations.
Affected versions:
Spring HATEOAS 1.5.0 through 1.5.6; 2.3.0 through 2.3.4; 2.4.0 through 2.4.1; 2.5.0 through 2.5.2; 3.0.0 through 3.0.3.
Affected versions:
Spring HATEOAS 1.5.0 through 1.5.6; 2.3.0 through 2.3.4; 2.4.0 through 2.4.1; 2.5.0 through 2.5.2; 3.0.0 through 3.0.3.
CVSS v3.1 Base Metrics — Score 7.5 (HIGH)
Attack VectorNetwork
Attack ComplexityLow
Privileges RequiredNone
User InteractionNone
ScopeUnchanged
ConfidentialityNone
IntegrityNone
AvailabilityHigh
Affected & Patched Versions
- Vmware Spring Hateoas >= 1.5.0 and < 1.5.7
- Vmware Spring Hateoas >= 2.3.0 and < 2.3.5
- Vmware Spring Hateoas >= 2.4.0 and < 2.4.2
- Vmware Spring Hateoas >= 2.5.0 and < 2.5.2.1
- Vmware Spring Hateoas >= 3.0.0 and < 3.0.3.1
- Vmware Spring Hateoas 1.5.7
- Vmware Spring Hateoas 2.3.5
- Vmware Spring Hateoas 2.4.2
- Vmware Spring Hateoas 2.5.2.1
- Vmware Spring Hateoas 3.0.3.1