cbcvebase.
CVE-2026-22737
published 2026-03-20

CVE-2026-22737: Use of Java scripting engine enabled (e.g. JRuby, Jython) template views in Spring MVC and Spring WebFlux applications can result in disclosure of content from…

PriorityP433medium5.9CVSS 3.1
AVNACHPRNUINSUCHINAN
EPSS
0.39%
30.9th percentile
Use of Java scripting engine enabled (e.g. JRuby, Jython) template views in Spring MVC and Spring WebFlux applications can result in disclosure of content from files outside the configured locations for script template views. This issue affects Spring Framework: from 7.0.0 through 7.0.5, from 6.2.0 through 6.2.16, from 6.1.0 through 6.1.25, from 5.3.0 through 5.3.46.

Affected

9 ranges
VendorProductVersion rangeFixed in
debianlibspring-java
springspring_framework5.3.0 – 5.3.46
springspring_framework6.1.0 – 6.1.25
springspring_framework6.2.0 – 6.2.16
springspring_framework7.0.0 – 7.0.5
vmwarespring_framework< 5.3.475.3.47
vmwarespring_framework>= 6.1.0 < 6.1.266.1.26
vmwarespring_framework>= 6.2.0 < 6.2.176.2.17
vmwarespring_framework>= 7.0.0 < 7.0.67.0.6

CVSS provenance

nvdv3.15.9MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
osv5.9MEDIUM
vendor_debian5.9LOW
vendor_redhat5.9MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.