CVE-2026-22737Disclosure(vmware / spring_framework)

LOWCVSS 5.9 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch vmware spring_framework systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Use of Java scripting engine enabled (e.g. JRuby, Jython) template views in Spring MVC and Spring WebFlux applications can result in disclosure of content from files outside the configured locations for script template views. This issue affects Spring Framework: from 7.0.0 through 7.0.5, from 6.2.0 through 6.2.16, from 6.1.0 through 6.1.25, from 5.3.0 through 5.3.46.

0.5/ 10 priority

Sources & remediation

Vendor / third-party advisories
Weakness type (CWE)
CWE-22

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • spring_framework

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 4 signals
  • Disclosure: 3 classified signals
  • Peaked 1d ago at 3 mentions (2026-03-20); latest day: 1
  • 4 total mentions across 2 days

Affected systems

Vendors
Products
spring_framework

Deep dive

Activity timeline4 mentions / 2d
01223Mentions · 2026-03-20: 3Mentions · 2026-05-15: 1Patch / Workaround · 2026-03-20: 1Technical Details · 2026-03-20: 3Technical Details · 2026-05-15: 103-2005-15
Signal classification2 categories
Disclosure
375.0%
Patch
125.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-03-203
Disclosure2Patch1
2026-05-151
Disclosure1
Full discourse4 posts
  • Gray Hats@the_yellow_fall
    Patch

    Researchers found two flaws in Spring Framework (CVE-2026-22737 & CVE-2026-22735) allowing path bypasses and stream corruption. Patch your apps today. #SpringFramework #JavaSecurity #CVE #CyberSecurity #InfoSec #Vulnerability #AppSec #SpringMVC #PatchAlert https://securityonline.info/spring-framework-vulnerabilities-path-bypass-sse-corruption-cve-2026-22737/ https://t.co/FAfMGd3iR1

    Post summary

    Researchers identified two Spring Framework vulnerabilities that enable path bypass and stream corruption, and users are urged to apply patches promptly.

    01092406
    10.7K followersView on X
  • Israel@f1tym1
    Disclosure

    CVE-2026-22737 | VMware Spring Framework up to 5.3.46/6.1.25/6.2.16/7.0.5 Template View information disclosure (Nessus ID 303353 / WID-SEC-2026-0796) https://ift.tt/yHgtoCR A vulnerability was found in VMware Spring Framework up to 5.3.46/6.1.25/6.2.16/7.0.5. It has been decla…

    Post summary

    A new information‑disclosure vulnerability, CVE‑2026‑22737, affecting VMware Spring Framework versions up to 7.0.5 has been reported; no PoC, exploit, or mitigation information is provided.

    0000049
    974 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-22737 Use of Java scripting engine enabled (e.g. JRuby, Jython) template views in Spring MVC and Spring WebFlux applications can result in disclosure of content from files … https://www.cve.org/CVERecord?id=CVE-2026-22737

    Post summary

    The post announces a new vulnerability (CVE-2026-22737) in Spring MVC and Spring WebFlux that permits disclosure of file contents via scripting engine template views, without providing PoC, exploit code, or patch details.

    00000110
    56.8K followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-22737 - Spring Framework Improper Path Limitation with Script View Templates Intel Report: https://ift.tt/SrlI1iF

    Post summary

    A new CVE (CVE-2026-22737) affecting the Spring Framework’s path limitation in Script View Templates is announced, with a link to an intel report but no PoC, exploit, patch, or active exploitation details.

    0000032
    334 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appvmwarespring_framework---

Explore more