LIVE · cybersecurity feed
Live wire
cve recordmedium

CVE-2026-22737

vmware · spring framework

Published
CVSS5.9
Severitymedium
WeaknessCWE-22
ExploitedNot in CISA KEV

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N

Description

Use of Java scripting engine enabled (e.g. JRuby, Jython) template views in Spring MVC and Spring WebFlux applications can result in disclosure of content from files outside the configured locations for script template views. This issue affects Spring Framework: from 7.0.0 through 7.0.5, from 6.2.0 through 6.2.16, from 6.1.0 through 6.1.25, from 5.3.0 through 5.3.46.

References

← Back to the CVE Tracker

Our coverage of CVE-2026-22737

No stories yet. This page updates automatically when we publish reporting that references CVE-2026-22737.