Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-41843

Опубликовано: 09 июн. 2026
Источник: redhat
CVSS3: 5.9
EPSS Низкий

Описание

Spring MVC and WebFlux applications are vulnerable to Path Traversal attacks when resolving static resources. Affected versions: Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; 6.1.0 through 6.1.27; 5.3.0 through 5.3.48.

A flaw was found in Spring Framework. Specifically, Spring MVC and WebFlux applications are vulnerable to a Path Traversal attack. This vulnerability allows a remote attacker to access sensitive files or directories on the server by manipulating requests for static resources. The successful exploitation of this flaw could lead to unauthorized information disclosure.

Отчет

This Moderate impact flaw in Spring Framework's MVC and WebFlux components allows a remote attacker to perform path traversal. Successful exploitation, while requiring high attack complexity, could lead to unauthorized information disclosure by accessing sensitive files or directories when applications resolve static resources.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat build of Apache Camel - HawtIO 4spring-webfluxFix deferred
Red Hat build of Apache Camel - HawtIO 4spring-webmvcFix deferred
Red Hat build of Quarkusquarkus-spring-webmvc-apiOut of support scope
Red Hat Data Grid 8spring-webmvcFix deferred
Red Hat Enterprise Linux 8log4j:2/log4jFix deferred
Red Hat Enterprise Linux 8pki-core:10.6/resteasyFix deferred
Red Hat Enterprise Linux 8pki-deps:10.6/resteasyFix deferred
Red Hat Enterprise Linux 9resteasyFix deferred
Red Hat Fuse 7org.apache.servicemix.bundles.spring-webmvcOut of support scope
Red Hat Fuse 7spring-webfluxOut of support scope

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-22
https://bugzilla.redhat.com/show_bug.cgi?id=2486714spring-webflux: spring-webmvc: Spring Framework: Information Disclosure via Path Traversal

EPSS

Процентиль: 30%
0.00369
Низкий

5.9 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.9
ubuntu
3 месяца назад

Spring MVC and WebFlux applications are vulnerable to Path Traversal attacks when resolving static resources. Affected versions: Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; 6.1.0 through 6.1.27; 5.3.0 through 5.3.48.

CVSS3: 5.9
nvd
3 месяца назад

Spring MVC and WebFlux applications are vulnerable to Path Traversal attacks when resolving static resources. Affected versions: Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; 6.1.0 through 6.1.27; 5.3.0 through 5.3.48.

CVSS3: 5.9
debian
3 месяца назад

Spring MVC and WebFlux applications are vulnerable to Path Traversal a ...

CVSS3: 5.9
github
3 месяца назад

Spring Framework Path Traversal via Versioned Static Resources in Spring MVC and WebFlux

EPSS

Процентиль: 30%
0.00369
Низкий

5.9 Medium

CVSS3

Уязвимость CVE-2026-41843