[High] CVE-2026-41006 – Spring HATEOAS's internal PropertyUtils.createObjectFromProperties method, used ...
High CVE-2026-41006 Spring HATEOAS's internal PropertyUtils.createObjectFromProperties method, used by the Collection+JSON and UBER media type deserializers, performs bean property binding via reflection without consulting Jackson access-control annotations. Affected versions: Spring HATEOAS 1.5.0...