Path traversal in Spring Framework - CVE-2026-47884
Published: August 28, 2026
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to improper path limitation in XsltView when rendering views through a catch-all "/**" mapping without an explicitly specified view name. A remote attacker can send a specially crafted request to execute arbitrary code.
The issue can also lead to server-side request forgery.
Affected software
Library Support for Spring
How to mitigate CVE-2026-47884
Library Support for Spring - update to 3.5.19