Spring HATEOAS's internal PropertyUtils.createObjectFromProperties method, used by the Collection+JSON and UBER media type deserializers, performs bean property binding via reflection without consulting Jackson access-control annotations.
Affected versions: Spring HATEOAS 1.5.0 through 1.5.6; 2.3.0 through 2.3.4; 2.4.0 through 2.4.1; 2.5.0 through 2.5.2; 3.0.0 through 3.0.3.
{
"github_reviewed_at": "2026-07-29T18:02:37Z",
"severity": "HIGH",
"cwe_ids": [
"CWE-284"
],
"github_reviewed": true,
"nvd_published_at": "2026-06-09T05:16:34Z"
}