A zip-slip path traversal vulnerability in Spring Data Geode's import snapshot functionality allows attackers to write files outside the intended extraction directory. This vulnerability appears to be susceptible on Windows OS only.
Metrics
Affected Vendors & Products
References
History
Fri, 20 Feb 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A zip-slip path traversal vulnerability in Spring Data Geode's import snapshot functionality allows attackers to write files outside the intended extraction directory. This vulnerability appears to be susceptible on Windows OS only. | |
| Title | Zip Slip Path Traversal in Snapshot Archive Extraction (Windows-Specific) | |
| Weaknesses | CWE-23 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: HeroDevs
Published:
Updated: 2026-02-20T16:03:21.032Z
Reserved: 2026-02-19T17:07:41.627Z
Link: CVE-2026-2818
No data.
Status : Received
Published: 2026-02-20T17:25:57.980
Modified: 2026-02-20T17:25:57.980
Link: CVE-2026-2818
No data.
OpenCVE Enrichment
No data.