PT-2026-21245 · Vmware · Spring Data Gemfire +1

Published

2026-02-20

·

Updated

2026-02-20

·

CVE-2026-2818

CVSS v3.1
8.2
VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:H/A:N
A zip-slip path traversal vulnerability in Spring Data Geode's import snapshot functionality allows attackers to write files outside the intended extraction directory. This vulnerability appears to be susceptible on Windows OS only.

Fix

Relative Path Traversal

Weakness Enumeration

Related Identifiers

CVE-2026-2818

Affected Products

Spring Data Gemfire
Spring Data Geode