CVE-2026-22737

Source
https://cve.org/CVERecord?id=CVE-2026-22737
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-22737.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2026-22737
Aliases
Downstream
Related
Published
2026-03-19T23:53:59.918Z
Modified
2026-05-05T16:29:51.060763Z
Severity
  • 5.9 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N CVSS Calculator
Summary
Spring Framework Improper Path Limitation with Script View Templates
Details

Use of Java scripting engine enabled (e.g. JRuby, Jython) template views in Spring MVC and Spring WebFlux applications can result in disclosure of content from files outside the configured locations for script template views. This issue affects Spring Framework: from 7.0.0 through 7.0.5, from 6.2.0 through 6.2.16, from 6.1.0 through 6.1.25, from 5.3.0 through 5.3.46.

Database specific
{
    "unresolved_ranges": [
        {
            "source": "AFFECTED_FIELD",
            "extracted_events": [
                {
                    "introduced": "7.0.0"
                },
                {
                    "last_affected": "7.0.5"
                },
                {
                    "introduced": "6.2.0"
                },
                {
                    "last_affected": "6.2.16"
                },
                {
                    "introduced": "6.1.0"
                },
                {
                    "last_affected": "6.1.25"
                },
                {
                    "introduced": "5.3.0"
                },
                {
                    "last_affected": "5.3.46"
                }
            ]
        },
        {
            "source": "DESCRIPTION",
            "extracted_events": [
                {
                    "introduced": "7.0.0"
                },
                {
                    "fixed": "7.0.5"
                },
                {
                    "introduced": "6.2.0"
                },
                {
                    "fixed": "6.2.16"
                },
                {
                    "introduced": "6.1.0"
                },
                {
                    "fixed": "6.1.25"
                },
                {
                    "introduced": "5.3.0"
                },
                {
                    "fixed": "5.3.46"
                }
            ]
        }
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/22xxx/CVE-2026-22737.json",
    "cna_assigner": "vmware"
}
References

Affected packages

Git / github.com/spring-projects/spring-framework

Affected ranges

Type
GIT
Repo
https://github.com/spring-projects/spring-framework
Events
Database specific
{
    "cpe": "cpe:2.3:a:vmware:spring_framework:*:*:*:*:*:*:*:*",
    "source": "CPE_FIELD",
    "extracted_events": [
        {
            "introduced": "6.2.0"
        },
        {
            "fixed": "6.2.17"
        },
        {
            "introduced": "7.0.0"
        },
        {
            "fixed": "7.0.6"
        }
    ]
}

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-22737.json"