CVE-2026-41843
5.9
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Exploitability: 2.2 / Impact: 3.6
Source: security@vmware.com (Secondary)
Description
Spring MVC and WebFlux applications are vulnerable to Path Traversal attacks when resolving static resources.
Affected versions:
Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; 6.1.0 through 6.1.27; 5.3.0 through 5.3.48.
Affected (4)
Products: Vmware: Spring Framework
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| From 5.3.0 to 5.3.49 |
References (1)
Timeline
No history available yet.