Perwendel · Sparkjava · CVE-2026-17459
**Name of the Vulnerable Software and Affected Versions**
perwendel spark versions prior to 2.9.5
**Description**
A flaw in the SparkJava component allows remote attackers to trigger symlink following. This occurs within the `staticFiles.externalLocation` function located in the `src/main/java/spark/resource/ExternalResourceHandler.jav` file. Symlink following is a condition where the application follows a symbolic link to access files outside the intended directory.
**Recommendations**
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
As a temporary workaround, restrict the use of the `staticFiles.externalLocation` function to minimize the risk of exploitation.