Vulnerability Details CVE-2026-41006
Spring HATEOAS's internal PropertyUtils.createObjectFromProperties method, used by the Collection+JSON and UBER media type deserializers, performs bean property binding via reflection without consulting Jackson access-control annotations.
Affected versions:
Spring HATEOAS 1.5.0 through 1.5.6; 2.3.0 through 2.3.4; 2.4.0 through 2.4.1; 2.5.0 through 2.5.2; 3.0.0 through 3.0.3.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.0
EPSS Ranking 12.8%
CVSS Severity
CVSS v3 Score 7.5
Products affected by CVE-2026-41006
-
cpe:2.3:a:vmware:spring_hateoas:*
-
cpe:2.3:a:vmware:spring_hateoas:1.5.0
-
cpe:2.3:a:vmware:spring_hateoas:1.5.1
-
cpe:2.3:a:vmware:spring_hateoas:1.5.2
-
cpe:2.3:a:vmware:spring_hateoas:1.5.3
-
cpe:2.3:a:vmware:spring_hateoas:1.5.4
-
cpe:2.3:a:vmware:spring_hateoas:1.5.5