Path traversal in Spring Framework - CVE-2026-41843

 

Path traversal in Spring Framework - CVE-2026-41843

Published: August 28, 2026


Vulnerability identifier: #VU146173
CSH Severity: Medium
CVSS v4: 8.2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-41843
CWE-ID: CWE-22
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to path traversal in static resource resolution in Spring MVC and WebFlux when handling requests for versioned static resources served from the file system. A remote attacker can send malicious requests to disclose sensitive information.

Exploitation requires that versioned resources support is configured and that the attacker knows or can guess metadata information for targeted resources.


Affected software

Spring Framework

How to mitigate CVE-2026-41843

Install security update from vendor's website.

Spring Framework - addressed in versions 5.3.49, 6.1.28, 6.2.18.1, 6.2.19, 7.0.7.1, 7.0.8

External References

Related Security Bulletins