Use of Java scripting engine enabled (e.g. JRuby, Jython) template views in Spring MVC and Spring WebFlux applications can result in disclosure of content from files outside the configured locations for script template views. This issue affects Spring Framework: from 7.0.0 through 7.0.5, from 6.2.0 through 6.2.16, from 6.1.0 through 6.1.25, from 5.3.0 through 5.3.46.
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://spring.io/security/cve-2026-22737 |
|
History
Fri, 20 Mar 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-22 | |
| Metrics |
ssvc
|
Fri, 20 Mar 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-20 CWE-22 |
Fri, 20 Mar 2026 11:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-20 CWE-22 |
Fri, 20 Mar 2026 09:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Spring
Spring spring Framework |
|
| Vendors & Products |
Spring
Spring spring Framework |
Fri, 20 Mar 2026 00:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Use of Java scripting engine enabled (e.g. JRuby, Jython) template views in Spring MVC and Spring WebFlux applications can result in disclosure of content from files outside the configured locations for script template views. This issue affects Spring Framework: from 7.0.0 through 7.0.5, from 6.2.0 through 6.2.16, from 6.1.0 through 6.1.25, from 5.3.0 through 5.3.46. | |
| Title | Spring Framework Improper Path Limitation with Script View Templates | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: vmware
Published: 2026-03-19T23:53:59.918Z
Updated: 2026-03-20T14:43:50.722Z
Reserved: 2026-01-09T06:54:49.674Z
Link: CVE-2026-22737
Updated: 2026-03-20T14:43:46.392Z
Status : Awaiting Analysis
Published: 2026-03-20T00:16:15.837
Modified: 2026-03-20T15:16:16.047
Link: CVE-2026-22737
No data.