PT-2026-21245 · Vmware · Spring Data Geode

Published

2026-02-20

·

Updated

2026-02-20

·

CVE-2026-2818

CVSS v3.1

8.2

High

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:H/A:N
Name of the Vulnerable Software and Affected Versions Spring Data Geode (affected versions not specified)
Description A zip-slip path traversal flaw exists in the import snapshot functionality of Spring Data Geode. This issue allows attackers to write files outside the intended extraction directory by crafting malicious archive files (ZIP files). The vulnerability appears to be susceptible on Windows OS only. The flaw could potentially lead to overwriting critical system files or sensitive data.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Relative Path Traversal

Weakness Enumeration

Related Identifiers

CVE-2026-2818

Affected Products

Spring Data Geode