Bypassed Boundaries: Two New Vulnerabilities Threaten Spring Framework Apps
ID: 56fd9531-e1f2-5dc3-aea8-279c15876d8e
STIX ID: report--56fd9531-e1f2-5dc3-aea8-279c15876d8e
Feed Name: securityonline.info
Threat Score
Security researchers disclosed two vulnerabilities in the Spring Framework: CVE-2026-22737 (an improper path limitation when using script-based template views that can allow reading files outside intended locations) and CVE-2026-22735 (Server-Sent Event stream corruption via injected characters). Affected branches include Spring 7.0.x, 6.2.x, 6.1.x, and 5.3.x, and fixed versions are 7.0.6, 6.2.17, 6.1.26, and 5.3.47; organizations are urged to upgrade promptly.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
