A zip-slip path traversal vulnerability in Spring Data Geode's import snapshot functionality allows attackers to write files outside the intended extraction directory. This vulnerability appears to be susceptible on Windows OS only.
History

Sat, 21 Feb 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-22
References
Metrics threat_severity

None

threat_severity

Important


Fri, 20 Feb 2026 21:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 20 Feb 2026 16:30:00 +0000

Type Values Removed Values Added
Description A zip-slip path traversal vulnerability in Spring Data Geode's import snapshot functionality allows attackers to write files outside the intended extraction directory. This vulnerability appears to be susceptible on Windows OS only.
Title Zip Slip Path Traversal in Snapshot Archive Extraction (Windows-Specific)
Weaknesses CWE-23
References
Metrics cvssV3_1

{'score': 8.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:H/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: HeroDevs

Published:

Updated: 2026-02-20T20:12:35.205Z

Reserved: 2026-02-19T17:07:41.627Z

Link: CVE-2026-2818

cve-icon Vulnrichment

Updated: 2026-02-20T20:12:24.717Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-02-20T17:25:57.980

Modified: 2026-02-20T18:57:15.973

Link: CVE-2026-2818

cve-icon Redhat

Severity : Important

Publid Date: 2026-02-20T16:03:21Z

Links: CVE-2026-2818 - Bugzilla

cve-icon OpenCVE Enrichment

No data.