High severity7.5NVD Advisory· Published Jun 9, 2026· Updated Jun 11, 2026
CVE-2026-41006
CVE-2026-41006
Description
Spring HATEOAS's internal PropertyUtils.createObjectFromProperties method, used by the Collection+JSON and UBER media type deserializers, performs bean property binding via reflection without consulting Jackson access-control annotations.
Affected versions: Spring HATEOAS 1.5.0 through 1.5.6; 2.3.0 through 2.3.4; 2.4.0 through 2.4.1; 2.5.0 through 2.5.2; 3.0.0 through 3.0.3.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1- Range: ≥1.5.0,≤1.5.6;≥2.3.0,≤2.3.4;≥2.4.0,≤2.4.1;≥2.5.0,≤2.5.2;≥3.0.0,≤3.0.3
Patches
Vulnerability mechanics
References
1- spring.io/security/cve-2026-41006nvdVendor Advisory
News mentions
0No linked articles in our index yet.