logo

Bypassed Boundaries: Two New Vulnerabilities Threaten Spring Framework Apps

ID: 56fd9531-e1f2-5dc3-aea8-279c15876d8e

STIX ID: report--56fd9531-e1f2-5dc3-aea8-279c15876d8e

Feed Name: securityonline.info

Threat Score
55/100

Date Published: 2026-03-20

Date Updated: 2026-04-23

Author: Ddos

...
...

Security researchers disclosed two vulnerabilities in the Spring Framework: CVE-2026-22737 (an improper path limitation when using script-based template views that can allow reading files outside intended locations) and CVE-2026-22735 (Server-Sent Event stream corruption via injected characters). Affected branches include Spring 7.0.x, 6.2.x, 6.1.x, and 5.3.x, and fixed versions are 7.0.6, 6.2.17, 6.1.26, and 5.3.47; organizations are urged to upgrade promptly.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.