Path Traversal Vulnerability in Spring Framework by VMware
CVE-2026-41843

5.9MEDIUM

Key Information:

Vendor

Spring

Vendor
CVE Published:
9 June 2026

What is CVE-2026-41843?

Spring MVC and WebFlux applications are vulnerable to Path Traversal attacks, allowing attackers to access unauthorized files and directories on the server. This vulnerability occurs when static resources are improperly resolved, enabling malicious actors to craft requests that traverse the directory structure, potentially exposing sensitive information. It is crucial for developers using affected versions of the Spring Framework to apply necessary patches and review security configurations to mitigate this risk.

Affected Version(s)

Spring Framework 7.0.0 < 7.0.7.1

Spring Framework 6.2.0 < 6.2.18.1

Spring Framework 6.1.0 < 6.1.28

References

CVSS V3.1

Score:
5.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.