← Back to CVE List
CVE-2026-22737NVD
Vulnerability Summary
Use of Java scripting engine enabled (e.g. JRuby, Jython) template views in Spring MVC and Spring WebFlux applications can result in disclosure of content from files outside the configured locations for script template views. This issue affects Spring Framework: from 7.0.0 through 7.0.5, from 6.2.0 through 6.2.16, from 6.1.0 through 6.1.25, from 5.3.0 through 5.3.46.
CVSS v3.1 Base Metrics — Score 5.9 (MEDIUM)
Attack VectorNetwork
Attack ComplexityHigh
Privileges RequiredNone
User InteractionNone
ScopeUnchanged
ConfidentialityHigh
IntegrityNone
AvailabilityNone
Affected & Patched Versions
- Vmware Spring Framework < 5.3.47
- Vmware Spring Framework >= 6.1.0 and < 6.1.26
- Vmware Spring Framework >= 6.2.0 and < 6.2.17
- Vmware Spring Framework >= 7.0.0 and < 7.0.6
- Vmware Spring Framework 5.3.47
- Vmware Spring Framework 6.1.26
- Vmware Spring Framework 6.2.17
- Vmware Spring Framework 7.0.6