CVE 8.2 HIGH

Zip Slip Path Traversal in Snapshot Archive Extraction (Windows-Specific)_CVE-2026-2818

8.2 / 10
HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:H/A:N

Description

A zip-slip path traversal vulnerability in Spring Data Geode's import snapshot functionality allows attackers to write files outside the intended extraction directory. This vulnerability appears to be susceptible on Windows OS only.

Basic Information

ID CVE-2026-2818
Source HeroDevs
Published Feb 20, 2026 at 16:03

Affected Product

Vendor VMware
Product Spring Data Geode
Version 2.0.0.RELEASE
Affected Versions VMware Spring Data Geode 2.0.0.RELEASE
VMware Spring Data Gemfire 1.7.0.RELEASE

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.