Path traversal in Spring Framework - CVE-2026-41843
Published: August 28, 2026
Vulnerability details
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to path traversal in static resource resolution in Spring MVC and WebFlux when handling requests for versioned static resources served from the file system. A remote attacker can send malicious requests to disclose sensitive information.
Exploitation requires that versioned resources support is configured and that the attacker knows or can guess metadata information for targeted resources.