← Back

CVE-2026-2818

nvd nist
Published: Feb 20, 2026Modified: Jul 15, 2026Deferred

JSON object

Loading...
8.2
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:H/A:N
Exploitability: 2.8 / Impact: 4.7
Source: 36c7be3b-2937-45df-85ea-ca7133ea542c (Secondary)

Description

A zip-slip path traversal vulnerability in Spring Data Geode's import snapshot functionality allows attackers to write files outside the intended extraction directory. This vulnerability appears to be susceptible on Windows OS only.

References (4)

Source: 36c7be3b-2937-45df-85ea-ca7133ea542c
Source: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
Source: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c

Timeline

No history available yet.