CVE-2026-17459 Details
Description
A vulnerability was determined in perwendel spark up to 2.9.4. This vulnerability affects the function staticFiles.externalLocation of the file src/main/java/spark/resource/ExternalResourceHandler.jav of the component SparkJava. Executing a manipulation can lead to symlink following. It is possible to launch the attack remotely. The exploit has been publicly disclosed and may be utilized. The project was informed of the problem early through an issue report but has not responded yet.
A path traversal vulnerability has been identified in SparkJava versions through 2.9.4. The issue resides in the external static file handling, specifically within the 'staticFiles.externalLocation' function. The vulnerability allows for symlink following, enabling an attacker to read arbitrary local files outside the designated static root. This issue can be exploited remotely.
Users are advised to update to SparkJava versions after 2.9.4, where this vulnerability has been addressed.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jul 26, 2026CISA-ADP
Assessed Jul 27, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/perwendel/spark/ | [email protected] | ProductVendor |
| https://github.com/perwendel/spark/issues/1296 | [email protected] | ExploitIssue TrackingTechnical DescriptionVendor |
| https://vuldb.com/cve/CVE-2026-17459 | [email protected] | AdvisoryPermission Required |
| https://vuldb.com/submit/862468 | [email protected] | Issue TrackingPermission Required |
| https://vuldb.com/vuln/383321 | [email protected] | AdvisoryPermission Required |
| https://vuldb.com/vuln/383321/cti | [email protected] | Content Wall |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-59 | Improper Link Resolution Before File Access ('Link Following') | [email protected] |
| CWE-61 | UNIX Symbolic Link (Symlink) Following | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| perwendel spark | <= 2.9.4 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 27, 2026 | CVE Modified | CISA-ADP |
| Jul 26, 2026 | New CVE Received | [email protected] |
Volerion