VYPR
High severity7.5NVD Advisory· Published Jun 9, 2026· Updated Jun 11, 2026

CVE-2026-41006

CVE-2026-41006

Description

Spring HATEOAS's internal PropertyUtils.createObjectFromProperties method, used by the Collection+JSON and UBER media type deserializers, performs bean property binding via reflection without consulting Jackson access-control annotations.

Affected versions: Spring HATEOAS 1.5.0 through 1.5.6; 2.3.0 through 2.3.4; 2.4.0 through 2.4.1; 2.5.0 through 2.5.2; 3.0.0 through 3.0.3.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
org.springframework.hateoas:spring-hateoasMaven
>= 3.0.0, < 3.0.43.0.4
org.springframework.hateoas:spring-hateoasMaven
>= 2.5.0, < 2.5.32.5.3
org.springframework.hateoas:spring-hateoasMaven
>= 2.3.0, <= 2.3.4
org.springframework.hateoas:spring-hateoasMaven
<= 1.5.6
org.springframework.hateoas:spring-hateoasMaven
>= 2.4.0, <= 2.4.1

Affected products

2
  • cpe:2.3:a:vmware:spring_hateoas:*:*:*:*:*:*:*:*
    Range: >=1.5.0,<1.5.7
  • Range: ≥1.5.0,≤1.5.6;≥2.3.0,≤2.3.4;≥2.4.0,≤2.4.1;≥2.5.0,≤2.5.2;≥3.0.0,≤3.0.3

Patches

Vulnerability mechanics

References

11

News mentions

0

No linked articles in our index yet.