Back

HIGH

Spring HATEOAS Collection+JSON/UBER deserializers do not honor Jackson configuration

Published Jun 9, 2026

Description

Spring HATEOAS's internal PropertyUtils.createObjectFromProperties method, used by the Collection+JSON and UBER media type deserializers, performs bean property binding via reflection without consulting Jackson access-control annotations.

Affected versions: Spring HATEOAS 1.5.0 through 1.5.6; 2.3.0 through 2.3.4; 2.4.0 through 2.4.1; 2.5.0 through 2.5.2; 3.0.0 through 3.0.3.

Affected products

Remediation

No remediation recorded yet.

Metrics

Weaknesses (1)

References (11)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner vmware
Published Jun 9, 2026
Updated Jun 27, 2026
Reserved Apr 16, 2026
CISA Vulnrichment
Updated Jun 9, 2026
NVD
Status Analyzed
Modified Jul 23, 2026
Red Hat
Severity n/a
Public date n/a
GHSA-7FXC-486F-32Q9