VRT 391,192 CVEs tracked · 15,442 in RASP scope · data as of 18 hours ago

CVE-2026-41006

7.5 High Protected by RASP

Description

Spring HATEOAS's internal PropertyUtils.createObjectFromProperties method, used by the Collection+JSON and UBER media type deserializers, performs bean property binding via reflection without consulting Jackson access-control annotations. Affected versions: Spring HATEOAS 1.5.0 through 1.5.6; 2.3.0 through 2.3.4; 2.4.0 through 2.4.1; 2.5.0 through 2.5.2; 3.0.0 through 3.0.3.

CWE-284 · Improper access control

Exploitation Status

No public exploit

Nothing published shows this CVE being exploited, which is not the same as ruling it out.

CVSS E:U

  • CISA KEV not listed
  • CISA Vulnrichment exploitation: none
  • Indexed PoC none indexed
  • EPSS 0.28% chance in 30 days

Waratek Defense Posture

Protected by RASP

A Waratek agent blocks this today.

Applicable rule: Promoted to MITIGATED-BY-RASP (security rule): this CVE's description identifies a deserialization vulnerability that can be mitigated by an ARMR deserialization security rule at the JVM level, without requiring a CVE-specific patch. Matched by description (no specific CWE was assigned by NVD).

  • Protection full a general security rule for the vulnerability class
  • Action available security rule
  • Review automated inferred
  • Record active
Decided by secure-rule-match : A vulnerability class already blocked by an ARMR security rule
Finding Promoted to MITIGATED-BY-RASP (security rule): this CVE's description identifies a deserialization vulnerability that can be mitigated by an ARMR deserialization security rule at the JVM level, without requiring a CVE-specific patch. Matched by description (no specific CWE was assigned by NVD).

CVSS

7.5 HIGH v3.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H 1 metric

VRT selects the newest version's highest entry and publishes it as cvssScore, newest rather than largest because scores are not comparable across versions, and highest rather than first because the first entry is frequently a CNA placeholder scoring 0.0 over NVD's own analysis.

VersionScoreBandVectorAssignerType
CVSS 3.1 7.5 HIGH CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H security@vmware.com Secondary published

Affected Software & Releases

☕ Maven Library Packages

Artifact coordinates and fix boundaries from OSV.dev
Package CoordinateIntroducedFixedLast affected
org.springframework.hateoas:spring-hateoas 3.0.0 3.0.4 unbounded
org.springframework.hateoas:spring-hateoas 2.5.0 2.5.3 unbounded
org.springframework.hateoas:spring-hateoas 2.3.0 none 2.3.4
org.springframework.hateoas:spring-hateoas 0 none 1.5.6
org.springframework.hateoas:spring-hateoas 2.4.0 none 2.4.1

🖥️ Product CPEs & Version Ranges

2 product(s) over 10 version claims (uncapped)
SourceVendorProductSchemeAffected Versions
osv org.springframework.hateoas spring-hateoas generic ≤ 1.5.6 · ≥ 2.3.0 and ≤ 2.3.4 · ≥ 2.4.0 and ≤ 2.4.1 · ≥ 2.5.0 and < 2.5.3 · ≥ 3.0.0 and < 3.0.4
nvd vmware spring hateoas generic ≥ 1.5.0 and < 1.5.7 · ≥ 2.3.0 and < 2.3.5 · ≥ 2.4.0 and < 2.4.2 · ≥ 2.5.0 and < 2.5.2.1 · ≥ 3.0.0 and < 3.0.3.1

References

URLTags
https://github.com/spring-projects/spring-hateoas/issues/2515 WEB
https://github.com/spring-projects/spring-hateoas/issues/2516 WEB
https://github.com/spring-projects/spring-hateoas/issues/2517 WEB
https://github.com/spring-projects/spring-hateoas/commit/2c127edd741e43e6e6f06f4081af92d400209990 WEB
https://github.com/spring-projects/spring-hateoas/commit/87d73a7af52d70e51823f44a67371b7a8a54b7c1 WEB
https://github.com/spring-projects/spring-hateoas/commit/d8050eedca1c92e1839f18ec1f7e0eecfb511389 WEB
https://github.com/spring-projects/spring-hateoas PACKAGE
https://github.com/spring-projects/spring-hateoas/releases/tag/2.5.3 WEB
https://github.com/spring-projects/spring-hateoas/releases/tag/3.0.4 WEB
https://spring.io/security/cve-2026-41006 WEB

Timeline

Published 2026-06-09 Last modified 2026-07-23
Published2026-06-09By the CVE Program.
NVD record modified2026-07-23NVD's own last-modified date for this record.