A zip-slip path traversal vulnerability in Spring Data Geode's import snapshot functionality allows attackers to write files outside the intended extraction directory. This vulnerability appears to be susceptible on Windows OS only.
Metrics
Affected Vendors & Products
References
History
Sat, 21 Feb 2026 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-22 | |
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Fri, 20 Feb 2026 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 20 Feb 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A zip-slip path traversal vulnerability in Spring Data Geode's import snapshot functionality allows attackers to write files outside the intended extraction directory. This vulnerability appears to be susceptible on Windows OS only. | |
| Title | Zip Slip Path Traversal in Snapshot Archive Extraction (Windows-Specific) | |
| Weaknesses | CWE-23 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: HeroDevs
Published: 2026-02-20T16:03:21.032Z
Updated: 2026-02-20T20:12:35.205Z
Reserved: 2026-02-19T17:07:41.627Z
Link: CVE-2026-2818
Updated: 2026-02-20T20:12:24.717Z
Status : Awaiting Analysis
Published: 2026-02-20T17:25:57.980
Modified: 2026-02-20T18:57:15.973
Link: CVE-2026-2818