A zip-slip path traversal vulnerability in Spring Data Geode's import snapshot functionality allows attackers to write files outside the intended extraction directory. This vulnerability appears to be susceptible on Windows OS only.
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Fri, 20 Feb 2026 21:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 20 Feb 2026 16:30:00 +0000

Type Values Removed Values Added
Description A zip-slip path traversal vulnerability in Spring Data Geode's import snapshot functionality allows attackers to write files outside the intended extraction directory. This vulnerability appears to be susceptible on Windows OS only.
Title Zip Slip Path Traversal in Snapshot Archive Extraction (Windows-Specific)
Weaknesses CWE-23
References
Metrics cvssV3_1

{'score': 8.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:H/A:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: HeroDevs

Published:

Updated: 2026-02-20T20:12:35.205Z

Reserved: 2026-02-19T17:07:41.627Z

Link: CVE-2026-2818

cve-icon Vulnrichment

Updated: 2026-02-20T20:12:24.717Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-02-20T17:25:57.980

Modified: 2026-02-20T18:57:15.973

Link: CVE-2026-2818

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses