CVE-2026-22737
published 2026-03-20CVE-2026-22737: Use of Java scripting engine enabled (e.g. JRuby, Jython) template views in Spring MVC and Spring WebFlux applications can result in disclosure of content from…
PriorityP433medium5.9CVSS 3.1
AVNACHPRNUINSUCHINAN
EPSS
0.39%
30.9th percentile
Use of Java scripting engine enabled (e.g. JRuby, Jython) template views in Spring MVC and Spring WebFlux applications can result in disclosure of content from files outside the configured locations for script template views. This issue affects Spring Framework: from 7.0.0 through 7.0.5, from 6.2.0 through 6.2.16, from 6.1.0 through 6.1.25, from 5.3.0 through 5.3.46.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | libspring-java | — | — |
| spring | spring_framework | 5.3.0 – 5.3.46 | — |
| spring | spring_framework | 6.1.0 – 6.1.25 | — |
| spring | spring_framework | 6.2.0 – 6.2.16 | — |
| spring | spring_framework | 7.0.0 – 7.0.5 | — |
| vmware | spring_framework | < 5.3.47 | 5.3.47 |
| vmware | spring_framework | >= 6.1.0 < 6.1.26 | 6.1.26 |
| vmware | spring_framework | >= 6.2.0 < 6.2.17 | 6.2.17 |
| vmware | spring_framework | >= 7.0.0 < 7.0.6 | 7.0.6 |
CVSS provenance
nvdv3.15.9MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
osv5.9MEDIUM
vendor_debian5.9LOW
vendor_redhat5.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
Spring Framework: Spring Framework: Information disclosure via Java scripting engine enabled template views
vendor_redhat·2026-03-19·CVSS 5.9
CVE-2026-22737 [MEDIUM] CWE-22 Spring Framework: Spring Framework: Information disclosure via Java scripting engine enabled template views
Spring Framework: Spring Framework: Information disclosure via Java scripting engine enabled template views
Use of Java scripting engine enabled (e.g. JRuby, Jython) template views in Spring MVC and Spring WebFlux applications can result in disclosure of content from files outside the configured locations for script template views. This issue affects Spring Framework: from 7.0.0 through 7.0.5, from 6.2.0 through 6.2.16, from 6.1.0 through 6.1.25, from 5.3.0 through 5.3.46.
A flaw was found in Spring Framework. When Java scripting engine enabled template views (such as those using JRuby or Jython) are used in Spring MVC and Spring WebFlux applications, a remote attacker can exploit this to disclose sensitive content from files located outside the intended script template view directories.
Debian
CVE-2026-22737: libspring-java - Use of Java scripting engine enabled (e.g. JRuby, Jython) template views in Spri...
vendor_debian·2026·CVSS 5.9
CVE-2026-22737 [MEDIUM] CVE-2026-22737: libspring-java - Use of Java scripting engine enabled (e.g. JRuby, Jython) template views in Spri...
Use of Java scripting engine enabled (e.g. JRuby, Jython) template views in Spring MVC and Spring WebFlux applications can result in disclosure of content from files outside the configured locations for script template views. This issue affects Spring Framework: from 7.0.0 through 7.0.5, from 6.2.0 through 6.2.16, from 6.1.0 through 6.1.25, from 5.3.0 through 5.3.46.
Scope: local
bookworm: open
bullseye: open
forky: open
sid: open
trixie: open
OSV
CVE-2026-22737: Use of Java scripting engine enabled (e
osv·2026-03-20·CVSS 5.9
CVE-2026-22737 [MEDIUM] CVE-2026-22737: Use of Java scripting engine enabled (e
Use of Java scripting engine enabled (e.g. JRuby, Jython) template views in Spring MVC and Spring WebFlux applications can result in disclosure of content from files outside the configured locations for script template views. This issue affects Spring Framework: from 7.0.0 through 7.0.5, from 6.2.0 through 6.2.16, from 6.1.0 through 6.1.25, from 5.3.0 through 5.3.46.
GHSA
Spring Framework Improper Path Limitation with Script View Templates
ghsa·2026-03-20
CVE-2026-22737 [MEDIUM] CWE-22 Spring Framework Improper Path Limitation with Script View Templates
Spring Framework Improper Path Limitation with Script View Templates
Use of Java scripting engine enabled (e.g. JRuby, Jython) template views in Spring MVC and Spring WebFlux applications can result in disclosure of content from files outside the configured locations for script template views. This issue affects Spring Framework: from 7.0.0 through 7.0.5, from 6.2.0 through 6.2.16, from 6.1.0 through 6.1.25, from 5.3.0 through 5.3.46.
OSV
Spring Framework Improper Path Limitation with Script View Templates
osv·2026-03-20
CVE-2026-22737 [MEDIUM] Spring Framework Improper Path Limitation with Script View Templates
Spring Framework Improper Path Limitation with Script View Templates
Use of Java scripting engine enabled (e.g. JRuby, Jython) template views in Spring MVC and Spring WebFlux applications can result in disclosure of content from files outside the configured locations for script template views. This issue affects Spring Framework: from 7.0.0 through 7.0.5, from 6.2.0 through 6.2.16, from 6.1.0 through 6.1.25, from 5.3.0 through 5.3.46.
No detection rules found.
No public exploits indexed.
Wiz
CVE-2026-22735 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 6.3
CVE-2026-22735 [MEDIUM] CVE-2026-22735 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-22735 :
Apache Log4j vulnerability analysis and mitigation
Spring MVC and WebFlux applications are vulnerable to stream corruption when using Server-Sent Events (SSE). This issue affects Spring Foundation: from 7.0.0 through 7.0.5, from 6.2.0 through 6.2.16, from 6.1.0 through 6.1.25, from 5.3.0 through 5.3.46.
Source : NVD
## 2.6
Score
Published March 20, 2026
Severity LOW
CNA Score 2.6
Affected Technologies
Apache Log4j
Wolfi
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 7.3
Exploitation Probability (EPSS) N/A
Affected packages and libraries
kafbat-ui
kafbat-ui-fips
Sources
NVD
Chainguard Has Fix Added at: Mar 29, 2026
Debian 11, 12, 13, 14 Severity LOW No Fix
Wiz
CVE-2026-22737 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 6.3
CVE-2026-22737 [MEDIUM] CVE-2026-22737 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-22737 :
Apache Log4j vulnerability analysis and mitigation
Use of Java scripting engine enabled (e.g. JRuby, Jython) template views in Spring MVC and Spring WebFlux applications can result in disclosure of content from files outside the configured locations for script template views. This issue affects Spring Framework: from 7.0.0 through 7.0.5, from 6.2.0 through 6.2.16, from 6.1.0 through 6.1.25, from 5.3.0 through 5.3.46.
Source : NVD
## 5.9
Score
Published March 20, 2026
Severity MEDIUM
CNA Score 5.9
Affected Technologies
Apache Log4j
Wolfi
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 19.5
Exploitation Probability (EPSS) 0.1
Affected packages and libraries
log4j:
Bugzilla
CVE-2026-22737 Spring Framework: Spring Framework: Information disclosure via Java scripting engine enabled template views
bugzilla·2026-03-20·CVSS 5.9
CVE-2026-22737 [MEDIUM] CVE-2026-22737 Spring Framework: Spring Framework: Information disclosure via Java scripting engine enabled template views
CVE-2026-22737 Spring Framework: Spring Framework: Information disclosure via Java scripting engine enabled template views
Use of Java scripting engine enabled (e.g. JRuby, Jython) template views in Spring MVC and Spring WebFlux applications can result in disclosure of content from files outside the configured locations for script template views. This issue affects Spring Framework: from 7.0.0 through 7.0.5, from 6.2.0 through 6.2.16, from 6.1.0 through 6.1.25, from 5.3.0 through 5.3.46.
2026-03-20
Published