CVE-2026-59282 affects multiple packages. Spring Framework applications that use Spring's data binding infrastructure to apply user-supplied property paths onto a target object may be vulnerable to a Denial of Service (DoS) attack. See references for individual vulnerability details.