{"id":"CVE-2026-41006","description":"Spring HATEOAS's internal PropertyUtils.createObjectFromProperties method, used by the Collection+JSON and UBER media type deserializers, performs bean property binding via reflection without consulting Jackson access-control annotations.\n\nAffected versions:\nSpring HATEOAS 1.5.0 through 1.5.6; 2.3.0 through 2.3.4; 2.4.0 through 2.4.1; 2.5.0 through 2.5.2; 3.0.0 through 3.0.3.","cvssScore":7.5,"cvssVersion":"3.1","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","cvssMetrics":[{"version":"3.1","score":7.5,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","source":"security@vmware.com","type":"Secondary"}],"cwes":["CWE-284"],"resolved":"MITIGATED-BY-RASP","published":"2026-06-09","lastModified":"2026-07-23","affectedProducts":[{"vendor":"vmware","product":"spring hateoas","versionStart":"\u003e=1.5.0","versionEnd":"\u003c1.5.7"},{"vendor":"vmware","product":"spring hateoas","versionStart":"\u003e=2.3.0","versionEnd":"\u003c2.3.5"},{"vendor":"vmware","product":"spring hateoas","versionStart":"\u003e=2.4.0","versionEnd":"\u003c2.4.2"},{"vendor":"vmware","product":"spring hateoas","versionStart":"\u003e=2.5.0","versionEnd":"\u003c2.5.2.1"},{"vendor":"vmware","product":"spring hateoas","versionStart":"\u003e=3.0.0","versionEnd":"\u003c3.0.3.1"}],"totalAffectedProducts":1,"references":[{"url":"https://github.com/spring-projects/spring-hateoas/issues/2515","source":"osv","tags":["WEB"]},{"url":"https://github.com/spring-projects/spring-hateoas/issues/2516","source":"osv","tags":["WEB"]},{"url":"https://github.com/spring-projects/spring-hateoas/issues/2517","source":"osv","tags":["WEB"]},{"url":"https://github.com/spring-projects/spring-hateoas/commit/2c127edd741e43e6e6f06f4081af92d400209990","source":"osv","tags":["WEB"]},{"url":"https://github.com/spring-projects/spring-hateoas/commit/87d73a7af52d70e51823f44a67371b7a8a54b7c1","source":"osv","tags":["WEB"]},{"url":"https://github.com/spring-projects/spring-hateoas/commit/d8050eedca1c92e1839f18ec1f7e0eecfb511389","source":"osv","tags":["WEB"]},{"url":"https://github.com/spring-projects/spring-hateoas","source":"osv","tags":["PACKAGE"]},{"url":"https://github.com/spring-projects/spring-hateoas/releases/tag/2.5.3","source":"osv","tags":["WEB"]},{"url":"https://github.com/spring-projects/spring-hateoas/releases/tag/3.0.4","source":"osv","tags":["WEB"]},{"url":"https://spring.io/security/cve-2026-41006","source":"osv","tags":["WEB"]}],"reasoning":{"decidingSource":"secure-rule-match","decidingReason":"Promoted to MITIGATED-BY-RASP (security rule): this CVE's description identifies a deserialization vulnerability that can be mitigated by an ARMR deserialization security rule at the JVM level, without requiring a CVE-specific patch. Matched by description (no specific CWE was assigned by NVD).","verdicts":[{"rule":"rejected","stage":"identity","outcome":"no-match"},{"rule":"armr-patch-file","stage":"scope","outcome":"no-match"},{"rule":"armr-secure-rule-file","stage":"scope","outcome":"no-match"},{"rule":"manual-classification","stage":"scope","outcome":"no-match"},{"rule":"h2-history","stage":"scope","outcome":"no-match"},{"rule":"non-java-upstream","stage":"scope","outcome":"no-match"},{"rule":"oracle-component","stage":"scope","outcome":"no-match"},{"rule":"osv-maven","stage":"scope","outcome":"matched","status":"QUEUED-FOR-REVIEW","detail":"Maven packages: org.springframework.hateoas:spring-hateoas"},{"rule":"patch-hint","stage":"disposition","outcome":"no-match"},{"rule":"open-source-maven","stage":"disposition","outcome":"matched","status":"MITIGATION-CANDIDATE","detail":"Open-source Maven artifact indexed by OSV (Maven packages: org.springframework.hateoas:spring-hateoas). The source is public, which makes an ARMR patch rule a candidate; nothing here establishes that one can be written."},{"rule":"poc-derivable","stage":"disposition","outcome":"skipped"},{"rule":"no-exploit","stage":"disposition","outcome":"skipped"},{"rule":"secure-rule-match","stage":"disposition","outcome":"matched","status":"MITIGATED-BY-RASP","detail":"Description mentions \"deserialization\" — mitigable by an ARMR deserialization security rule (CWE not assigned).","decisive":true},{"rule":"below-action-threshold","stage":"disposition","outcome":"skipped"},{"rule":"no-exploit-published","stage":"disposition","outcome":"skipped"}],"affectedProducts":[{"vendor":"vmware","product":"spring_hateoas","isKnown":false,"cpe":"cpe:2.3:a:vmware:spring_hateoas:*:*:*:*:*:*:*:*"}],"affectedPackages":[{"name":"org.springframework.hateoas:spring-hateoas","introduced":"3.0.0","fixed":"3.0.4"},{"name":"org.springframework.hateoas:spring-hateoas","introduced":"2.5.0","fixed":"2.5.3"},{"name":"org.springframework.hateoas:spring-hateoas","introduced":"2.3.0","lastAffected":"2.3.4"},{"name":"org.springframework.hateoas:spring-hateoas","introduced":"0","lastAffected":"1.5.6"},{"name":"org.springframework.hateoas:spring-hateoas","introduced":"2.4.0","lastAffected":"2.4.1"}]},"assessment":{"record":{"state":"active"},"protection":{"level":"full","mechanisms":["security-rule"]},"action":{"state":"available","type":"security-rule"},"review":{"state":"automated","basis":"inferred"}},"signals":{"hasPOC":false,"pocCount":0},"kev":{"inKEV":false},"epss":{"available":true,"score":0.00277,"percentile":0.20041},"ssvc":{"available":true,"exploitation":"none","automatable":"yes","technicalImpact":"partial"}}