CVE-2026-22737 PUBLISHED

Spring Framework Improper Path Limitation with Script View Templates

Assigner: vmware
Reserved: 09.01.2026 Published: 19.03.2026 Updated: 20.03.2026

Use of Java scripting engine enabled (e.g. JRuby, Jython) template views in Spring MVC and Spring WebFlux applications can result in disclosure of content from files outside the configured locations for script template views. This issue affects Spring Framework: from 7.0.0 through 7.0.5, from 6.2.0 through 6.2.16, from 6.1.0 through 6.1.25, from 5.3.0 through 5.3.46.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS Score: 5.9

Product Status

Vendor Spring
Product Spring Framework
Versions Default: unaffected
  • affected from 7.0.0 to 7.0.5 (incl.)
  • affected from 6.2.0 to 6.2.16 (incl.)
  • affected from 6.1.0 to 6.1.25 (incl.)
  • affected from 5.3.0 to 5.3.46 (incl.)

References