logo

New Patches Secure Critical Spring HATEOAS Flaws

ID: d3e4b897-066a-55ac-8f2e-d31921fb6411

STIX ID: report--d3e4b897-066a-55ac-8f2e-d31921fb6411

Feed Name: securityonline.info

Threat Score
70/100

Date Published: 2026-06-12

Date Updated: 2026-06-12

Author: Do Son

...
...

Two critical Spring HATEOAS vulnerabilities (CVE-2026-41006 and CVE-2026-41007) were disclosed: a data-handling flaw that can bypass internal checks and allow unauthorized modification, and an unbounded static string cache that can be exploited to exhaust heap memory and crash servers; affected versions 1.5 through 3.0 should be upgraded to the patched releases (2.5.3 or 3.0.4) immediately.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.