Home
HIGH: 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HDefault status
unaffected
1.5.0 (custom) before 1.5.7
affected
2.3.0 (custom) before 2.3.5
affected
2.4.0 (custom) before 2.4.2
affected
2.5.0 (custom) before 2.5.3
affected
3.0.0 (custom) before 3.0.4
affected
Description
Spring HATEOAS maintains an unbounded static cache of StringLinkRelation instances keyed on attacker-supplied strings. Affected versions: Spring HATEOAS 1.5.0 through 1.5.6; 2.3.0 through 2.3.4; 2.4.0 through 2.4.1; 2.5.0 through 2.5.2; 3.0.0 through 3.0.3.
Problem types
CWE-770: Allocation of Resources Without Limits or Throttling
Product status
1.5.0 (custom) before 1.5.7
2.3.0 (custom) before 2.3.5
2.4.0 (custom) before 2.4.2
2.5.0 (custom) before 2.5.3
3.0.0 (custom) before 3.0.4
References
spring.io/security/cve-2026-41007