Path traversal in Spring Framework - CVE-2026-59280
Published: August 31, 2026
Vulnerability details
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to path traversal in SpringTemplateLoader when resolving a view name derived from untrusted input. A remote attacker can supply a crafted view name containing backslash sequences to disclose sensitive information.
Only applications that return a view name derived from untrusted input and use FreeMarker configured with SpringTemplateLoader are vulnerable.
Affected software
Library Support for Spring
How to mitigate CVE-2026-59280
Library Support for Spring - update to 3.5.19