CVE-2026-59280 - Spring Framework Path Traversal via Backslash in SpringTemplateLoader
Brief
CVE ID : CVE-2026-59280
Published : Aug. 27, 2026, 4:41 p. m.
- 32 minutes ago
Description : Applications using Spring Framework's FreeMarker integration may be vulnerable to a path traversal attack when a controller returns a view name derived from untrusted input and FreeMarker is configured to resolve templates through SpringTemplateLoader. Spring Framework 7.
- 0 - 7.
- 8 Spring Framework 6.
- 0 - 6.
- 19 Spring Framework 6.
- 0 - 6.
- 28 Spring Framework 6.
- 0 - 6.
- 30 Spring Framework 5.
- 0 - 5.
- 49 Spring Framework 5.
- 25. RELEASE and earlier
Severity: 0.0
- NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
