A zip-slip path traversal vulnerability in Spring Data Geode's import snapshot functionality allows attackers to write files outside the intended extraction directory. This vulnerability appears to be susceptible on Windows OS only.
References
Configurations
No configuration.
History
20 Feb 2026, 17:25
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-02-20 17:25
Updated : 2026-02-20 18:57
NVD link : CVE-2026-2818
Mitre link : CVE-2026-2818
CVE.ORG link : CVE-2026-2818
JSON object : View
Products Affected
No product.
CWE
CWE-23
Relative Path Traversal
