PT-2026-21245 · Vmware · Spring Data Geode
Published
2026-02-20
·
Updated
2026-02-20
·
CVE-2026-2818
CVSS v3.1
8.2
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Spring Data Geode (affected versions not specified)
Description
A zip-slip path traversal flaw exists in the import snapshot functionality of Spring Data Geode. This issue allows attackers to write files outside the intended extraction directory by crafting malicious archive files (ZIP files). The vulnerability appears to be susceptible on Windows OS only. The flaw could potentially lead to overwriting critical system files or sensitive data.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Relative Path Traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Spring Data Geode