Path traversal in Spring Framework - CVE-2026-22737
Published: April 28, 2026
Vulnerability details
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to improper path limitation in script view templates when rendering views with Java scripting engine enabled and the view name is not explicitly specified. A remote attacker can send a specially crafted request to disclose sensitive information.
Exploitation requires a mapping for "/**" that results in view rendering.
Affected software
Library Support for Spring
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
CICS Transaction Gateway for Multiplatforms
CICS Transaction Gateway Desktop Edition
MongoDB Enterprise Advanced with IBM
IBM Sterling Connect:Direct for Microsoft Windows
How to mitigate CVE-2026-22737
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - update to 5.3.1 Patch 5
MongoDB Enterprise Advanced with IBM - update to 1.16.0
IBM Sterling Connect:Direct for Microsoft Windows - addressed in versions 6.3.0.6.45, 6.4.0.4.17
External References
Related Security Bulletins
- Multiple vulnerabilities in Spring Framework
- Multiple vulnerabilities in IBM Sterling Connect:Direct for Microsoft Windows
- IBM Watson Speech Services Cartridge update for Spring MVC and WebFlux
- Multiple vulnerabilities in IBM Library Support for Spring
- MongoDB Enterprise Advanced with IBM update for Spring Framework
- Multiple vulnerabilities in IBM CICS Transaction Gateway for Multiplatforms
- Multiple vulnerabilities in CICS Transaction Gateway Desktop Edition