CVE-2026-22737

NameCVE-2026-22737
DescriptionUse of Java scripting engine enabled (e.g. JRuby, Jython) template views in Spring MVC and Spring WebFlux applications can result in disclosure of content from files outside the configured locations for script template views. This issue affects Spring Framework: from 7.0.0 through 7.0.5, from 6.2.0 through 6.2.16, from 6.1.0 through 6.1.25, from 5.3.0 through 5.3.46.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
libspring-java (PTS)bullseye4.3.30-1vulnerable
bookworm4.3.30-2vulnerable
trixie4.3.30-3vulnerable
forky, sid4.3.30-4vulnerable

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
libspring-javasource(unstable)(unfixed)unimportant

Notes

https://spring.io/security/cve-2026-22737
Only supported for building applications shipped in Debian, see README.Debian.security

Search for package or bug name: Reporting problems