Spring Framework MVC applications deployed as WAR or with embedded Servlet containers that do not reject suspicious URI sequences and serve static resources with Spring resource handling contain a path traversal vulnerability, letting attackers access unauthorized files, exploit requires non-compliant Servlet container configuration.
id: CVE-2025-41242
info:
name: Spring Framework - Path Traversal
author: DhiyaneshDk
severity
...