CVE-2026-2818 Details
Description
A zip-slip path traversal vulnerability in Spring Data Geode's import snapshot functionality allows attackers to write files outside the intended extraction directory. This vulnerability appears to be susceptible on Windows OS only.
A zip-slip path traversal vulnerability has been identified in Spring Data Geode's snapshot import feature, specifically on Windows operating systems. This vulnerability allows attackers to write files outside the designated extraction directory. It affects multiple versions of Spring Data Geode and Spring Data GemFire.
Users can upgrade to the Never-Ending Support (NES) version for Spring Data Geode offered by HeroDevs. As an interim measure, it is recommended to validate the integrity and origin of snapshot archives before importing, avoid importing from untrusted sources, and run the application with minimal filesystem permissions to reduce the impact of arbitrary file writes.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Feb 20, 2026CISA-ADP
Assessed Feb 20, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2026-2818 | redhat-SADP | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2441384 | redhat-SADP | |
| https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-2818.json | redhat-SADP | |
| https://www.herodevs.com/vulnerability-directory/cve-2026-2818 | HeroDevs | AdvisoryRemedy |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-22 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') | redhat-SADP |
| CWE-23 | Relative Path Traversal | HeroDevs |
Affected Products
| Product | Versions |
|---|---|
| Spring Data Geode | All versions |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 15, 2026 | CVE Modified | redhat-SADP |
| Jun 30, 2026 | CVE Modified | redhat-SADP |
| Jun 17, 2026 | CVE Modified | HeroDevs |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Feb 20, 2026 | New CVE Received | HeroDevs |
Volerion