VYPR
High severity7.5NVD Advisory· Published Jun 9, 2026· Updated Jun 11, 2026

CVE-2026-41006

CVE-2026-41006

Description

Spring HATEOAS's internal PropertyUtils.createObjectFromProperties method, used by the Collection+JSON and UBER media type deserializers, performs bean property binding via reflection without consulting Jackson access-control annotations.

Affected versions: Spring HATEOAS 1.5.0 through 1.5.6; 2.3.0 through 2.3.4; 2.4.0 through 2.4.1; 2.5.0 through 2.5.2; 3.0.0 through 3.0.3.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

1
  • Range: ≥1.5.0,≤1.5.6;≥2.3.0,≤2.3.4;≥2.4.0,≤2.4.1;≥2.5.0,≤2.5.2;≥3.0.0,≤3.0.3

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.