VYPR
High severity7.5NVD Advisory· Published Jun 9, 2026· Updated Jun 11, 2026

CVE-2026-41007

CVE-2026-41007

Description

Spring HATEOAS maintains an unbounded static cache of StringLinkRelation instances keyed on attacker-supplied strings.

Affected versions: Spring HATEOAS 1.5.0 through 1.5.6; 2.3.0 through 2.3.4; 2.4.0 through 2.4.1; 2.5.0 through 2.5.2; 3.0.0 through 3.0.3.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
org.springframework.hateoas:spring-hateoasMaven
>= 3.0.0, < 3.0.43.0.4
org.springframework.hateoas:spring-hateoasMaven
>= 2.5.0, < 2.5.32.5.3
org.springframework.hateoas:spring-hateoasMaven
>= 2.3.0, <= 2.3.4
org.springframework.hateoas:spring-hateoasMaven
<= 1.5.6
org.springframework.hateoas:spring-hateoasMaven
>= 2.4.0, <= 2.4.1

Affected products

2
  • cpe:2.3:a:vmware:spring_hateoas:*:*:*:*:*:*:*:*
    Range: >=1.5.0,<1.5.7
  • Range: >=1.5.0, <=1.5.6; >=2.3.0, <=2.3.4; >=2.4.0, <=2.4.1; >=2.5.0, <=2.5.2; >=3.0.0, <=3.0.3

Patches

Vulnerability mechanics

References

11

News mentions

0

No linked articles in our index yet.