CVE-2026-41007
7.5 HIGHSpring HATEOAS maintains an unbounded static cache of StringLinkRelation instances keyed on attacker-supplied strings
Published: 2026-06-09 · Last updated: 2026-06-09
Severity and scoring
- CVSS
- 7.5 HIGH
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- CWE
- CWE-770
Description
Spring HATEOAS maintains an unbounded static cache of StringLinkRelation instances keyed on attacker-supplied strings. Affected versions: Spring HATEOAS 1.5.0 through 1.5.6; 2.3.0 through 2.3.4; 2.4.0 through 2.4.1; 2.5.0 through 2.5.2; 3.0.0 through 3.0.3.
Source: NVD
References
Related CVEs
Same CWE
- CVE-2026-53460 — ImageMagick is free and open-source software used for editing and manipulating digital images (7.5 HIGH)
- CVE-2026-46702 — Russh is a Rust SSH client & server library (7.5 HIGH)
- CVE-2026-46673 — Russh is a Rust SSH client & server library (7.5 HIGH)
- CVE-2026-45031 — ImageMagick is free and open-source software used for editing and manipulating digital images (5.3 MEDIUM)
- CVE-2026-10740 — Unbounded memory allocation in the CRYPTO frame reassembler in s2n-quic before 1.8.2 may allow an unauthenticated remote actor to cause a... (5.3 MEDIUM)