PT-2026-26455 · Spring · Spring Framework

G2H

+1

·

Published

2026-03-19

·

Updated

2026-03-20

·

CVE-2026-22737

CVSS v3.1

5.9

Medium

AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Use of Java scripting engine enabled (e.g. JRuby, Jython) template views in Spring MVC and Spring WebFlux applications can result in disclosure of content from files outside the configured locations for script template views. This issue affects Spring Framework: from 7.0.0 through 7.0.5, from 6.2.0 through 6.2.16, from 6.1.0 through 6.1.25, from 5.3.0 through 5.3.46.

Fix

Related Identifiers

CVE-2026-22737

Affected Products

Spring Framework