CVE-2026-59294
Last modified
CVE-2026-59294 is a medium-severity vulnerability rated 6.5/10 on the CVSS scale. ResourceCacheService.getCacheName() builds the on-disk filename by appending the URI fragment verbatim, without stripping path separators or .. sequences, and passes the result to new File(resourceParentFolder, newFileName) before writing the downloaded bytes there. Spring AI 2.0.0 Spring AI 1.1.0 - 1.1.8 Spring AI 1.0.9 and earlier. EPSS estimates a 0.25% chance of exploitation in the next 30 days.
Description
ResourceCacheService.getCacheName() builds the on-disk filename by appending the URI fragment verbatim, without stripping path separators or .. sequences, and passes the result to new File(resourceParentFolder, newFileName) before writing the downloaded bytes there. Spring AI 2.0.0 Spring AI 1.1.0 - 1.1.8 Spring AI 1.0.9 and earlier
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Vmware | Spring Ai | < 1.0.10 |
| Vmware | Spring Ai | >= 1.1.0, < 1.1.9 |
| Vmware | Spring Ai | >= 2.0.0, < 2.0.0.1 |
References
- https://spring.io/security/cve-2026-59294Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2026-59294?
How severe is CVE-2026-59294?
How do I fix CVE-2026-59294?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-59287Spring for GraphQL is vulnerable to Denial of Service attack…5.9
- CVE-2026-59288The GraphiQL page bundled with Spring for GraphQL sends requ…7.4
- CVE-2026-59289Spring for GraphQL's Spring Data pagination support resolves…7.5
- CVE-2026-59291Potential arbitrary file read and SSRF vulnerability in Spri…5.5
- CVE-2026-59292PropertiesPersistingMetadataStore, the default file-based Co…3.2
- CVE-2026-59293Unless the application explicitly raises smbMinVersion, the …6.6
- CVE-2026-59295It is possible for outbound HTTP requests using a Micrometer…5.9
- CVE-2026-59296Using untrusted, non-normalized input as-is for metrics data…5.9
- CVE-2026-59297Implementation of isSecure() call of ServerlessHttpServletRe…3.5
- CVE-2026-59298Potential for improper filtering of HTTP headers in Spring C…3.5
- CVE-2026-59299Composition lookup can potentially poison base function in S…3.5
- CVE-2026-59300Potential for logging sensitive data in Spring Cloud Functio…3.5
Are you affected by CVE-2026-59294?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
