cbcvebase.
CVE-2026-22737
published 2026-03-20

CVE-2026-22737: Use of Java scripting engine enabled (e.g. JRuby, Jython) template views in Spring MVC and Spring WebFlux applications can result in disclosure of content from…

medium5.9CVSS 3.1
AVNACHPRNUINSUCHINAN
Use of Java scripting engine enabled (e.g. JRuby, Jython) template views in Spring MVC and Spring WebFlux applications can result in disclosure of content from files outside the configured locations for script template views. This issue affects Spring Framework: from 7.0.0 through 7.0.5, from 6.2.0 through 6.2.16, from 6.1.0 through 6.1.25, from 5.3.0 through 5.3.46.

Affected

9 ranges
VendorProductVersion rangeFixed in
debianlibspring-java
springspring_framework5.3.0 – 5.3.46
springspring_framework6.1.0 – 6.1.25
springspring_framework6.2.0 – 6.2.16
springspring_framework7.0.0 – 7.0.5
vmwarespring_framework< 5.3.475.3.47
vmwarespring_framework>= 6.1.0 < 6.1.266.1.26
vmwarespring_framework>= 6.2.0 < 6.2.176.2.17
vmwarespring_framework>= 7.0.0 < 7.0.67.0.6

CVSS provenance

nvdv3.15.9MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
osv5.9MEDIUM