CVE-2016-9878: Pivotal Software Spring Framework

High severity, CVSS 7.5. EPSS: 5.7% chance of exploitation in the next 30 days.

An issue was discovered in Pivotal Spring Framework before 3.2.18, 4.2.x before 4.2.9, and 4.3.x before 4.3.5. Paths provided to the ResourceServlet were not properly sanitized and as a result exposed to directory traversal attacks.

Affected products

  • Pivotal Software Spring Framework: up to and including 3.2.0; version 4.2.0 only; version 4.3.0 only
  • VMware Spring Framework: version 3.2.1 only; version 3.2.2 only; version 3.2.3 only; version 3.2.4 only; version 3.2.5 only; version 3.2.6 only; …

Published 2016-12-29. Last modified 2026-06-17.