CVE-2026-22737: Spring Framework Improper Path Limitation with Script View Templates
Use of Java scripting engine enabled (e.g. JRuby, Jython) template views in Spring MVC and Spring WebFlux applications can result in disclosure of content from files outside the configured locations for script template views. This issue affects Spring Framework: from 7.0.0 through 7.0.5, from 6.2.0 through 6.2.16, from 6.1.0 through 6.1.25, from 5.3.0 through 5.3.46.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
maven/org.springframework:spring-webfluxto a version that resolves this vulnerability.Fixed in 6.2.17 - Upgrade
Upgrade
maven/org.springframework:spring-webfluxto a version that resolves this vulnerability.Fixed in 7.0.6 - Upgrade
Upgrade
maven/org.springframework:spring-webmvcto a version that resolves this vulnerability.Fixed in 6.2.17 - Upgrade
Upgrade
maven/org.springframework:spring-webmvcto a version that resolves this vulnerability.Fixed in 7.0.6
Event History
Frequently Asked Questions
What is the severity of CVE-2026-22737?
CVE-2026-22737 is classified with a high severity due to the potential for unauthorized file content disclosure.
How do I fix CVE-2026-22737?
To fix CVE-2026-22737, update the Spring Framework to versions above 7.0.5, 6.2.16, 6.1.25, or 5.3.46.
What applications are affected by CVE-2026-22737?
CVE-2026-22737 affects applications using VMware Spring Framework versions between 5.3.0 and 5.3.46, 6.1.0 and 6.1.25, 6.2.0 and 6.2.16, and 7.0.0 and 7.0.5.
What type of vulnerability is CVE-2026-22737?
CVE-2026-22737 is an improper path limitation vulnerability that can allow content disclosure from unauthorized file locations.
Does CVE-2026-22737 affect both Spring MVC and Spring WebFlux?
Yes, CVE-2026-22737 affects both Spring MVC and Spring WebFlux applications that utilize Java scripting engine templates.