← Back

CVE-2026-22737

nvd nist
Published: Mar 20, 2026Modified: Jun 17, 2026

JSON object

Loading...
5.9
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Exploitability: 2.2 / Impact: 3.6
Source: security@vmware.com (Secondary)

Description

Use of Java scripting engine enabled (e.g. JRuby, Jython) template views in Spring MVC and Spring WebFlux applications can result in disclosure of content from files outside the configured locations for script template views. This issue affects Spring Framework: from 7.0.0 through 7.0.5, from 6.2.0 through 6.2.16, from 6.1.0 through 6.1.25, from 5.3.0 through 5.3.46.

Affected (4)

1 product
Spring Framework
Configuration A
4 vulnerable
Vulnerable SoftwareAffected Versions
Vmware
Before 5.3.47
From 6.1.0 to 6.1.26
From 6.2.0 to 6.2.17
From 7.0.0 to 7.0.6

References (1)

Source: security@vmware.com
Vendor Advisory

Timeline

No history available yet.