Unbounded Cache Vulnerability in Spring HATEOAS Product by Spring
CVE-2026-41007

7.5HIGH

Key Information:

Vendor

Spring

Vendor
CVE Published:
9 June 2026

What is CVE-2026-41007?

The Spring HATEOAS framework suffers from a significant vulnerability due to its management of an unbounded static cache for StringLinkRelation instances, which are keyed on attacker-controlled strings. This can potentially allow an attacker to disrupt application functionality, leading to denial-of-service conditions or other unintended behavior. It is crucial for users of affected Spring HATEOAS versions to implement recommended remediation steps to mitigate the risk associated with this vulnerability.

Affected Version(s)

Spring HATEOAS 1.5.0 < 1.5.7

Spring HATEOAS 2.3.0 < 2.3.5

Spring HATEOAS 2.4.0 < 2.4.2

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.