CVE-2026-2818

Publication date

2026-02-20 16:03:21

Family

HeroDevs

State

PUBLISHED

Description

A zip-slip path traversal vulnerability in Spring Data Geodes import snapshot functionality allows attackers to write files outside the intended extraction directory. This vulnerability appears to be susceptible on Windows OS only.