CVE-2026-41006

Severity CVSS v4.0:
Pending analysis
Type:
CWE-284 Improper Access Control
Publication date:
09/06/2026
Last modified:
23/07/2026

Description

Spring HATEOAS&amp;#39;s internal PropertyUtils.createObjectFromProperties method, used by the Collection+JSON and UBER media type deserializers, performs bean property binding via reflection without consulting Jackson access-control annotations.<br /> <br /> Affected versions:<br /> Spring HATEOAS 1.5.0 through 1.5.6; 2.3.0 through 2.3.4; 2.4.0 through 2.4.1; 2.5.0 through 2.5.2; 3.0.0 through 3.0.3.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:vmware:spring_hateoas:*:*:*:*:*:*:*:* 1.5.0 (including) 1.5.7 (excluding)
cpe:2.3:a:vmware:spring_hateoas:*:*:*:*:*:*:*:* 2.3.0 (including) 2.3.5 (excluding)
cpe:2.3:a:vmware:spring_hateoas:*:*:*:*:*:*:*:* 2.4.0 (including) 2.4.2 (excluding)
cpe:2.3:a:vmware:spring_hateoas:*:*:*:*:*:*:*:* 2.5.0 (including) 2.5.2.1 (excluding)
cpe:2.3:a:vmware:spring_hateoas:*:*:*:*:*:*:*:* 3.0.0 (including) 3.0.3.1 (excluding)


References to Advisories, Solutions, and Tools