Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-41843

Опубликовано: 09 июн. 2026
Источник: redhat
CVSS3: 5.9

Описание

Spring MVC and WebFlux applications are vulnerable to Path Traversal attacks when resolving static resources. Affected versions: Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; 6.1.0 through 6.1.27; 5.3.0 through 5.3.48.

A flaw was found in Spring Framework. Specifically, Spring MVC and WebFlux applications are vulnerable to a Path Traversal attack. This vulnerability allows a remote attacker to access sensitive files or directories on the server by manipulating requests for static resources. The successful exploitation of this flaw could lead to unauthorized information disclosure.

Отчет

This Moderate impact flaw in Spring Framework's MVC and WebFlux components allows a remote attacker to perform path traversal. Successful exploitation, while requiring high attack complexity, could lead to unauthorized information disclosure by accessing sensitive files or directories when applications resolve static resources.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat build of Apache Camel - HawtIO 4spring-webfluxFix deferred
Red Hat build of Apache Camel - HawtIO 4spring-webmvcFix deferred
Red Hat build of Quarkusquarkus-spring-webmvc-apiOut of support scope
Red Hat Data Grid 8spring-webmvcFix deferred
Red Hat Enterprise Linux 8log4j:2/log4jFix deferred
Red Hat Enterprise Linux 8pki-core:10.6/resteasyFix deferred
Red Hat Enterprise Linux 8pki-deps:10.6/resteasyFix deferred
Red Hat Enterprise Linux 9resteasyFix deferred
Red Hat Fuse 7org.apache.servicemix.bundles.spring-webmvcOut of support scope
Red Hat Fuse 7spring-webfluxOut of support scope

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-22
https://bugzilla.redhat.com/show_bug.cgi?id=2486714spring-webflux: spring-webmvc: Spring Framework: Information Disclosure via Path Traversal

5.9 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.9
ubuntu
около 2 месяцев назад

Spring MVC and WebFlux applications are vulnerable to Path Traversal attacks when resolving static resources. Affected versions: Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; 6.1.0 through 6.1.27; 5.3.0 through 5.3.48.

CVSS3: 5.9
nvd
около 2 месяцев назад

Spring MVC and WebFlux applications are vulnerable to Path Traversal attacks when resolving static resources. Affected versions: Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; 6.1.0 through 6.1.27; 5.3.0 through 5.3.48.

CVSS3: 5.9
debian
около 2 месяцев назад

Spring MVC and WebFlux applications are vulnerable to Path Traversal a ...

CVSS3: 5.9
github
около 2 месяцев назад

Spring MVC and WebFlux applications are vulnerable to Path Traversal attacks when resolving static resources. Affected versions: Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; 6.1.0 through 6.1.27; 5.3.0 through 5.3.48.

5.9 Medium

CVSS3