Back

HIGH

Spring HATEOAS heap exhaustion through unbounded internal caching

Published Jun 9, 2026

Description

Spring HATEOAS maintains an unbounded static cache of StringLinkRelation instances keyed on attacker-supplied strings.

Affected versions: Spring HATEOAS 1.5.0 through 1.5.6; 2.3.0 through 2.3.4; 2.4.0 through 2.4.1; 2.5.0 through 2.5.2; 3.0.0 through 3.0.3.

Affected products

Remediation

Red Hat statement

This is an Important denial of service flaw in Spring HATEOAS, affecting Red Hat JBoss Fuse. The vulnerability arises from an unbounded static cache that can be exhausted by attacker-supplied strings, leading to resource unavailability. This impact is considered Important due to the potential for remote, unauthenticated attackers to disrupt service.

Red Hat mitigation

To mitigate the risk of denial of service, restrict network access to applications that use Spring HATEOAS to trusted clients and networks. Implementing rate limiting on incoming requests can also help reduce the impact by limiting the volume of attacker-supplied strings that can trigger cache exhaustion. Ensure that any changes to network configurations are thoroughly tested to avoid disrupting legitimate service.

Metrics

References (14)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner vmware
Published Jun 9, 2026
Updated Jun 27, 2026
Reserved Apr 16, 2026
CISA Vulnrichment
Updated Jun 9, 2026
NVD
Status Analyzed
Modified Jul 23, 2026
Red Hat
Severity Important
Public date Jun 9, 2026
GHSA-439X-6767-44CV