CVE-2020-36321: Vaadin Flow

High severity, CVSS 7.5. EPSS: 1.2% chance of exploitation in the next 30 days.

Improper URL validation in development mode handler in com.vaadin:flow-server versions 2.0.0 through 2.4.1 (Vaadin 14.0.0 through 14.4.2), and 3.0 prior to 5.0 (Vaadin 15 prior to 18) allows attacker to request arbitrary files stored outside of intended frontend resources folder.

Affected products

  • Vaadin Flow: from 2.0.0, before 2.4.2 (fixed in 2.4.2); from 3.0.0, before 5.0.0 (fixed in 5.0.0)
  • Vaadin Vaadin: from 14.0.0, before 14.4.3 (fixed in 14.4.3); from 15.0.0, before 18.0.0 (fixed in 18.0.0)

Published 2021-04-23. Last modified 2026-06-17.