A zip-slip path traversal vulnerability in Spring Data Geode's import snapshot functionality allows attackers to write files outside the intended extraction directory. This vulnerability appears to be susceptible on Windows OS only.
Metrics
Affected Vendors & Products
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Fri, 20 Feb 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A zip-slip path traversal vulnerability in Spring Data Geode's import snapshot functionality allows attackers to write files outside the intended extraction directory. This vulnerability appears to be susceptible on Windows OS only. | |
| Title | Zip Slip Path Traversal in Snapshot Archive Extraction (Windows-Specific) | |
| Weaknesses | CWE-23 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: HeroDevs
Published:
Updated: 2026-02-20T16:03:21.032Z
Reserved: 2026-02-19T17:07:41.627Z
Link: CVE-2026-2818
No data.
Status : Received
Published: 2026-02-20T17:25:57.980
Modified: 2026-02-20T17:25:57.980
Link: CVE-2026-2818
No data.
OpenCVE Enrichment
No data.
Weaknesses